CVE-2026-40914
Description
A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. A user could successfully send a message to an address or consume a message from a queue with a routing-type not supported by the corresponding address when that operation should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address. Even though the user was already granted permission to send and/or consume messages, they should not be able to augment the routing-type of the address without the createAddress permission.
This issue affects Apache Artemis: from 2.50.0 through 2.53.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.54.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.artemis:artemis-stomp-protocolMaven | >= 2.50.0, < 2.54.0 | 2.54.0 |
org.apache.artemis:artemis-stomp-protocolMaven | >= 2.0.0, <= 2.44.0 | — |
Affected products
7- Range: from 2.0.0 through 2.44.0
- osv-coords4 versionspkg:apk/chainguard/wildfly-openjdk-17pkg:apk/chainguard/wildfly-openjdk-21pkg:apk/wolfi/wildfly-openjdk-17pkg:apk/wolfi/wildfly-openjdk-21
< 40.0.1-r3+ 3 more
- (no CPE)range: < 40.0.1-r3
- (no CPE)range: < 40.0.1-r3
- (no CPE)range: < 40.0.1-r3
- (no CPE)range: < 40.0.1-r3
Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2026/05/27/8nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-rf99-f9j2-gv3fghsaADVISORY
- lists.apache.org/thread/6q3st8dlorz2q05svqn11k1xl7jkmm4cnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-40914ghsaADVISORY
- github.com/apache/artemis/commit/53173375c4d5e4b57890e89d37ed8b666c974474ghsaWEB
- github.com/apache/artemis/pull/6395ghsaWEB
- issues.apache.org/jira/browse/ARTEMIS-5996ghsaWEB
News mentions
1- Apache Ships 12 Patches Across 7 Projects: Shiro, Airflow, Syncope Lead the BatchVypr Intelligence · May 28, 2026