CVE-2026-49362

🟡 Monitoruj

Nieautoryzowany atakujący może tworzyć dowolne kolejki w Apache Artemis, co prowadzi do manipulacji stanem brokera.

CVSS
7.5
EPSS
0.4%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-09-10 05:16:59 UTC
Ostatnia modyfikacja (NVD)2026-09-16 01:10:42 UTC
Referencje