PatchSiren cyber security CVE debrief
CVE-2026-49362 Apache CVE debrief
CVE-2026-49362 is a high-severity vulnerability affecting Apache Artemis and Apache ActiveMQ Artemis. An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, potentially leading to unauthorized broker state manipulation and denial of service. Affected versions include Apache Artemis from 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
- Vendor
- Apache
- Product
- Artemis
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-16
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-16
Who should care
Defenders responsible for Apache Artemis or Apache ActiveMQ Artemis deployments should assess exposure and prioritize upgrading to version 2.57.0 to mitigate this high-severity vulnerability.
Why it matters
CVE-2026-49362 is a high-severity vulnerability in Apache Artemis and Apache ActiveMQ Artemis that allows unauthorized broker state manipulation and potential denial of service. Defenders should prioritize upgrading to version 2.57.0 and assess exposure in their environments.
- Potential denial of service due to unauthorized broker state manipulation.
- Need to verify current versions and check for vulnerability in environments.
- Possible unauthorized broker state manipulation requiring mitigation.
Technical summary
The vulnerability allows an unauthenticated remote attacker to create arbitrary durable queues via the CORE protocol, potentially leading to unauthorized broker state manipulation and denial of service. Affected versions include Apache Artemis from 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis from 1.0.0 through 2.44.0. Defenders should prioritize upgrading to version 2.57.0 and assess exposure in their environments, particularly where Apache Artemis or Apache ActiveMQ Artemis are deployed, and verify if current versions are vulnerable.
Defensive priority
Defenders should prioritize upgrading to version 2.57.0 to mitigate this high-severity vulnerability. They should assess exposure in their environments, particularly where Apache Artemis or Apache ActiveMQ Artemis are deployed, and verify if current versions are vulnerable.
Recommended defensive actions
- Upgrade to version 2.57.0 of Apache Artemis or Apache ActiveMQ Artemis.
- Assess exposure in environments where Apache Artemis or Apache ActiveMQ Artemis are deployed.
- Verify current versions and check for vulnerability.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, affected versions, and recommended actions. However, there is limited information on potential exploitation or specific impacts beyond denial of service.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49362 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49362
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49362 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49362
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/3828w4tm5mfpflmoprb5oxfgwhq3xw0v
[email protected] - Mailing List, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.