Missing Authentication for Critical Function in Apache ActiveMQ Artemis and Apache Artemis - CVE-2026-57967
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to hijack an existing authenticated session and assume its ongoing execution.
The vulnerability exists due to missing authentication in CORE protocol session reattachment when processing a crafted SESSION_REATTACH packet. A remote attacker can send a crafted CORE protocol SESSION_REATTACH packet to hijack an existing authenticated session and assume its ongoing execution.
Affected software
Apache Artemis