Executive brief
Apache Artemis is a message broker used to route and store messages in enterprise applications. An attacker on the network can intercept the initial cluster setup handshake without authentication to steal administrative credentials, potentially gaining complete control over the message broker and access to all data flowing through it.
Technical details
This vulnerability involves credential exposure during the cluster connection handshake in Apache Artemis. An unauthenticated, network-adjacent attacker can intercept cluster discovery traffic to capture administrative credentials in plaintext or weakly protected form during the initial handshake. The attack requires network adjacency but no prior authentication. Successful exploitation grants an attacker administrative access to the Artemis cluster, enabling them to read/modify messages, configure the broker, or disrupt service. The issue affects Artemis 2.50.0–2.56.0 and ActiveMQ Artemis 1.0.0–2.44.0, with a fix available in Artemis 2.57.0.
Affected products
- Apache Artemis 2.50.0 through 2.56.0
- Apache ActiveMQ Artemis 1.0.0 through 2.44.0
Timeline
- 2026-09-10: disclosed: CVE-2026-49364 published
- 2026-09-10: patched: Fix available in Artemis 2.57.0