CVE-2026-49362
גבוהה 7.5
תיאור (מקור, אנגלית)
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-5/10/2026
- CWE
- CWE-306
מוצרים מושפעים
apache: artemis
קישורים
- https://lists.apache.org/thread/3828w4tm5mfpflmoprb5oxfgwhq3xw0v Mailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/09/10/1 Mailing ListThird Party Advisory