SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-57967

CRITICAL · CVSS 9.8 EPSS 0.55%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Apache Artemis and Apache ActiveMQ Artemis versions 2.50.0 through 2.56.0 and 1.0.0 through 2.44.0, respectively, are vulnerable to an unauthenticated remote attack that allows an attacker to hijack an existing session by crafting a specific CORE protocol SESSION_REATTACH packet. This vulnerability can lead to unauthorized access and execution of ongoing authenticated sessions, posing a significant risk to user data and system integrity. Organizations using the affected versions should prioritize upgrading to version 2.57.0 to mitigate this risk.

CVE
CVE-2026-57967
Severity
CRITICAL
CVSS
9.8
EPSS
0.55%
Apache

Original NVD Description

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.