PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49362 Apache CVE debrief

CVE-2026-49362 is a high-severity vulnerability affecting Apache Artemis and Apache ActiveMQ Artemis. An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, potentially leading to unauthorized broker state manipulation and denial of service. Affected versions include Apache Artemis from 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

Vendor
Apache
Product
Artemis
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-16
Advisory published
2026-09-10
Advisory updated
2026-09-16

Who should care

Defenders responsible for Apache Artemis or Apache ActiveMQ Artemis deployments should assess exposure and prioritize upgrading to version 2.57.0 to mitigate this high-severity vulnerability.

Why it matters

CVE-2026-49362 is a high-severity vulnerability in Apache Artemis and Apache ActiveMQ Artemis that allows unauthorized broker state manipulation and potential denial of service. Defenders should prioritize upgrading to version 2.57.0 and assess exposure in their environments.

  • Potential denial of service due to unauthorized broker state manipulation.
  • Need to verify current versions and check for vulnerability in environments.
  • Possible unauthorized broker state manipulation requiring mitigation.

Technical summary

The vulnerability allows an unauthenticated remote attacker to create arbitrary durable queues via the CORE protocol, potentially leading to unauthorized broker state manipulation and denial of service. Affected versions include Apache Artemis from 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis from 1.0.0 through 2.44.0. Defenders should prioritize upgrading to version 2.57.0 and assess exposure in their environments, particularly where Apache Artemis or Apache ActiveMQ Artemis are deployed, and verify if current versions are vulnerable.

Defensive priority

Defenders should prioritize upgrading to version 2.57.0 to mitigate this high-severity vulnerability. They should assess exposure in their environments, particularly where Apache Artemis or Apache ActiveMQ Artemis are deployed, and verify if current versions are vulnerable.

Recommended defensive actions

  • Upgrade to version 2.57.0 of Apache Artemis or Apache ActiveMQ Artemis.
  • Assess exposure in environments where Apache Artemis or Apache ActiveMQ Artemis are deployed.
  • Verify current versions and check for vulnerability.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, affected versions, and recommended actions. However, there is limited information on potential exploitation or specific impacts beyond denial of service.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49362 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49362

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49362 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49362

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.