CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6930

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers

CVE-2026-49364 affects Apache Artemis and Apache ActiveMQ Artemis versions 2.50.0 through 2.56.0 and 1.0.0 through 2.44.0 respectively, allowing unauthenticated network-adjacent attackers to access cluster credentials before authentication is established. The vulnerability carries important severity and impacts both the core client and server components of these message broker platforms.

Why it matters: Organizations running affected Artemis or ActiveMQ Artemis versions need to patch immediately, as cluster credentials can be exposed to peers on the network without authentication, potentially enabling lateral movement and cluster compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary