CVE-2026-49362EPSS p55.8%
CVE-2026-49362CVE-2026-49362
apache / artemis
Description
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.82% probability of exploitation · percentile 55.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-16 |