CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6931

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription

CVE-2026-49363 affects Apache Artemis and ActiveMQ Artemis, allowing unauthenticated attackers to discover cluster node details by submitting a SUBSCRIBE_TOPOLOGY request over the CORE protocol before completing authentication. Versions 2.50.0 through 2.56.0 of Artemis and 1.0.0 through 2.44.0 of ActiveMQ Artemis are vulnerable to this moderate severity flaw.

Why it matters: Organizations running affected Artemis or ActiveMQ Artemis versions face exposure of internal cluster topology to unauthenticated network attackers, which could facilitate further reconnaissance or attacks; patching or upgrading to fixed versions is required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary