PT-2026-26884 · Apache · Apache Artemis+1

Stephen Higgs

·

Published

2026-03-21

·

Updated

2026-03-24

·

CVE-2026-32642

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Artemis versions 2.50.0 through 2.52.0 Apache ActiveMQ Artemis versions 2.0.0 through 2.44.0
Description An authorization issue exists in Apache Artemis and Apache ActiveMQ Artemis. Specifically, when an application utilizing the OpenWire protocol attempts to establish a non-durable JMS topic subscription on a non-existent address, and the authenticated user possesses the "createDurableQueue" permission but lacks the "createAddress" permission, and address auto-creation is disabled, a temporary address is created. This occurs despite the subscription creation attempt should fail due to insufficient authorization to create the address. The temporary address is removed when the OpenWire connection is terminated.
Recommendations Upgrade to version 2.53.0 to resolve the issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-32642
GHSA-F4GC-MWRG-Q36R

Affected Products

Apache Activemq Artemis
Apache Artemis