PT-2026-26884 · Apache · Apache Artemis+1
Stephen Higgs
·
Published
2026-03-21
·
Updated
2026-03-24
·
CVE-2026-32642
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Artemis versions 2.50.0 through 2.52.0
Apache ActiveMQ Artemis versions 2.0.0 through 2.44.0
Description
An authorization issue exists in Apache Artemis and Apache ActiveMQ Artemis. Specifically, when an application utilizing the OpenWire protocol attempts to establish a non-durable JMS topic subscription on a non-existent address, and the authenticated user possesses the "createDurableQueue" permission but lacks the "createAddress" permission, and address auto-creation is disabled, a temporary address is created. This occurs despite the subscription creation attempt should fail due to insufficient authorization to create the address. The temporary address is removed when the OpenWire connection is terminated.
Recommendations
Upgrade to version 2.53.0 to resolve the issue.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Activemq Artemis
Apache Artemis