https://seclists.org/oss-sec/2026/q3/698: CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on COprotocol session attachment
Published Sep 9, 2026
·Updated
Affected Software
2 affected components
Apache ARTEMIS>=2.50.0<=2.56.0
Apache ActiveMQ Artemis>=1.0.0<=2.44.0
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker must be able to remotely reach the broker's CORE protocol service and craft a SESSION_REATTACH packet. No authentication is required for the attacker to attach to an existing session.
2
Who is exposed?
Deployments using Apache Artemis artemis-server versions 2.50.0 through 2.56.0 or Apache ActiveMQ Artemis artemis-server versions 1.0.0 through 2.44.0 are affected if a remote attacker can access the CORE protocol endpoint.
3
What is the recommended remediation?
Upgrade to Apache Artemis version 2.57.0, which fixes the issue.