Unrated severityNVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026
CVE-2026-49362
CVE-2026-49362
Description
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3>=1.0.0,<=2.44.0+ 1 more
- (no CPE)range: >=1.0.0,<=2.44.0
- (no CPE)range: from 1.0.0 through 2.44.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.