Insufficiently protected credentials in Apache ActiveMQ Artemis and Apache Artemis - CVE-2026-49364
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose cluster administrative credentials.
The vulnerability exists due to insufficiently protected credentials in the initial cluster connection handshake when using discovery to connect to a cluster peer. A remote attacker can leverage discovery to capture cluster administrative credentials.
Affected software
Apache Artemis