As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment
CVE-2026-57967 affects Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. An unauthenticated remote attacker can craft a malicious CORE protocol SESSION_REATTACH packet to hijack an existing authenticated session and execute commands within that session's privileges. The vulnerability stems from missing authentication checks on session reattachment functionality.
Why it matters: Organizations running affected Apache Artemis or ActiveMQ Artemis deployments face exposure to unauthenticated remote session hijacking, enabling attackers to execute operations with the privileges of legitimate users without credentials; patching or upgrading is required to block this attack vector.
- Source published
- First seen by Cybersecurity Tracker