CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6928

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment

CVE-2026-57967 affects Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. An unauthenticated remote attacker can craft a malicious CORE protocol SESSION_REATTACH packet to hijack an existing authenticated session and execute commands within that session's privileges. The vulnerability stems from missing authentication checks on session reattachment functionality.

Why it matters: Organizations running affected Apache Artemis or ActiveMQ Artemis deployments face exposure to unauthenticated remote session hijacking, enabling attackers to execute operations with the privileges of legitimate users without credentials; patching or upgrading is required to block this attack vector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary