Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bugbunny.Ai

#50955of 53,639
4.3Total CVSS
Vulnerabilities · 1
PT-2026-44367
4.3
2026-05-28
Apache · Apache Activemq Artemis · CVE-2026-40914
**Name of the Vulnerable Software and Affected Versions** Apache Artemis versions 2.50.0 through 2.53.0 Apache ActiveMQ Artemis versions 2.0.0 through 2.44.0 **Description** An issue exists where an application using the STOMP (Simple Text Oriented Messaging Protocol) protocol can augment the routing-type of an address. This occurs when security credentials grant either consume or send permissions on an address, allowing the user to perform these operations with a routing-type not supported by the address, even without the `createAddress` permission. Normally, such operations should be rejected if the user lacks the permission to change the routing-type. **Recommendations** Upgrade Apache Artemis to version 2.54.0. Upgrade Apache ActiveMQ Artemis to version 2.54.0.