Junglewise Threat Intelligence

CVE-2026-40914: Apache Artemis authorization bypass in STOMP protocol

CVE-2026-40914 · Severity: medium · CVSS 4.3 · Published 2026-05-28

Technologies: Apache Artemis, Apache Activemq Artemis. Vendors: Apache.

Executive brief

Apache Artemis, a high-performance message broker used for enterprise messaging, contains a security flaw in its handling of the STOMP protocol. Users with basic permissions to send or receive messages can bypass restrictions to modify how message addresses are routed, even if they lack the specific authority to create or manage those addresses. This could allow unauthorized users to alter message delivery behavior, potentially disrupting standard operations or bypassing intended architectural constraints.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the STOMP protocol implementation of Apache Artemis. The flaw stems from the STOMP component duplicating auto-creation logic instead of using the centralized ServerSession checkAutoCreate method. An authenticated attacker with 'send' or 'consume' permissions can provide a routing-type not supported by a specific address, effectively augmenting the address configuration without possessing the 'createAddress' permission. This allows for unauthorized modification of address metadata and routing behavior. The issue is resolved in version 2.54.0 by refactoring the STOMP implementation to utilize standard session authorization checks.

Affected products

  • Apache Artemis 2.50.0 - 2.53.0
  • Apache ActiveMQ Artemis 2.0.0 - 2.44.0

Timeline

  • 2026-04-29: patched: Fix merged into main branch
  • 2026-05-27: disclosed: Public disclosure on oss-security mailing list
  • 2026-05-28: advisory: GitHub Advisory and NVD entry published

References

Related threats