CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBETOPOLOGY request prior to authentication.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Artemis / Apache ActiveMQ Artemisto a version that resolves this vulnerability.Fixed in 2.57.0Patch CVE-2026-49363
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker only needs remote access to an Artemis endpoint that accepts the CORE protocol. No authentication is required before sending the SUBSCRIBE_TOPOLOGY request.
What information can be disclosed?
The attacker can discover cluster node details through the pre-authentication topology subscription request.
Which deployments should be prioritized for remediation?
Prioritize Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0 where remote clients can connect using the CORE protocol. Upgrade to version 2.57.0 to fix the issue.