SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-49363

HIGH · CVSS 7.5 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Apache Artemis and Apache ActiveMQ Artemis versions 2.50.0 to 2.56.0 and 1.0.0 to 2.44.0, respectively, are vulnerable to an unauthenticated remote attack that allows the disclosure of cluster node details via a SUBSCRIBE_TOPOLOGY request. This vulnerability could lead to information leakage that may aid in further attacks on the system. Organizations utilizing these versions should prioritize upgrading to version 2.57.0 to mitigate the risk.

CVE
CVE-2026-49363
Severity
HIGH
CVSS
7.5
EPSS
0.40%
Apache

Original NVD Description

An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.