PT-2026-26884 · Apache · Apache Activemq Artemis+1

Stephen Higgs

·

Publicado

2026-03-21

·

Atualizado

2026-06-15

·

CVE-2026-32642

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Artemis versions 2.50.0 through 2.52.0 Apache ActiveMQ Artemis versions 2.0.0 through 2.44.0
Description An authorization issue exists in Apache Artemis and Apache ActiveMQ Artemis. Specifically, when an application utilizing the OpenWire protocol attempts to establish a non-durable JMS topic subscription on a non-existent address, and the authenticated user possesses the "createDurableQueue" permission but lacks the "createAddress" permission, and address auto-creation is disabled, a temporary address is created. This occurs despite the subscription creation attempt should fail due to insufficient authorization to create the address. The temporary address is removed when the OpenWire connection is terminated.
Recommendations Upgrade to version 2.53.0 to resolve the issue.

Correção

DoS

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32642
GHSA-F4GC-MWRG-Q36R

Produtos afetados

Apache Activemq Artemis
Apache Artemis