PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49363 Apache Software Foundation CVE debrief

CVE-2026-49363 is a HIGH severity vulnerability affecting Apache Artemis and Apache ActiveMQ Artemis. An unauthenticated remote attacker can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. The issue affects Apache Artemis from 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

Vendor
Apache Software Foundation
Product
Apache Artemis
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-16
Advisory published
2026-09-10
Advisory updated
2026-09-16

Who should care

Defenders and administrators of Apache Artemis and Apache ActiveMQ Artemis should assess exposure and prioritize upgrading to version 2.57.0. They should also review and update affected versions, monitor for potential exploitation attempts, and verify affected deployments in managed environments. Security teams need to track exceptions and retest remediated assets.

Why it matters

CVE-2026-49363 is a HIGH severity vulnerability affecting Apache Artemis and Apache ActiveMQ Artemis, allowing unauthenticated remote attackers to discover cluster node details. Defenders and administrators should assess exposure, prioritize upgrading to version 2.57.0, and monitor for potential exploitation attempts.

  • Unauthenticated remote attackers can discover cluster node details
  • Potential information disclosure
  • Need to verify affected versions and upgrade to 2.57.0
  • Monitoring for exploitation attempts recommended

Technical summary

An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. The vulnerability allows unauthenticated remote attackers to discover cluster node details, potentially leading to information disclosure. Users are recommended to upgrade to version 2.57.0, which fixes the issue. Affected product deployments should be reviewed for exposure.

Defensive priority

Upgrade to version 2.57.0 to fix the issue

Recommended defensive actions

  • Upgrade to version 2.57.0
  • Review and update affected versions
  • Monitor for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its description, affected versions, and recommended actions. The issue affects Apache Artemis from 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis from 1.0.0 through 2.44.0. Defenders should verify affected versions, assess exposure, and prioritize upgrading to version 2.57.0. Evidence is limited to public CVE and NVD details.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49363 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49363

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49363 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49363

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.