wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof
cve CVE-2026-49364 2 sources, 2 claims · Watch
Red Hat writes:
wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof the claim
wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof the claim
What it is to other things
| affects | apache/artemis NVD |
| made_by | apache NVD |
In words only, so not counted until a person confirms one:
| affects | apache_software_foundation/apache_artemisNVD says “Apache Software Foundation · Apache Artemis” |
| made_by | apache_software_foundationNVD says “Apache Software Foundation” |
What each source says
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Cvss cvss conflict | NVD | 9.1receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.artemis:artemis-core-client",
"packageURL": "pkg:maven/org.apache.artemis/artemis-core-client",
"product": "Apache Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.56.0",
"status": "affected",
"version": "2.50.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.artemis:artemis-server",
"packageURL": "pkg:maven/org.apache.artemis/artemis-server",
"product": "Apache Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.56.0",
"status": "affected",
"version": "2.50.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.activemq:artemis-core-client",
"packageURL": "pkg:maven/org.apache.activemq/artemis-core-client",
"product": "Apache ActiveMQ Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.44.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.activemq:artemis-server",
"packageURL": "pkg:maven/org.apache.activemq/artemis-server",
"product": "Apache ActiveMQ Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.44.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B6E3F972-3247-4504-AFD9-833891228040",
"versionEndExcluding": "2.44.0",
"versionStartIncluding": "1.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A41D89AC-2573-4270-9C7C-21D85E1096FE",
"versionEndExcluding": "2.57.0",
"versionStartIncluding": "2.50.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.\n\nThis issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.\n\n\n\nUsers are recommended to upgrade to version 2.57.0, which fixes the issue."
}
],
"id": "CVE-2026-49364",
"lastModified": "2026-09-16T01:10:31.487",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-49364",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T15:54:10.664215Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-10T05:17:01.230",
"references": [
{
"source": "security@apache.org",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"url": "https://lists.apache.org/thread/4qbgcz3k38q30bfbf7hphtomrdc8l8n8"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"url": "http://www.openwall.com/lists/oss-security/2026/09/10/3"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-306"
}
],
"source": "security@apache.org",
"type": "Secondary"
}
]
}
} | — | ||||
| Cvss cvss conflict | Red Hat | 8receipt
What the source handed over{
"CVE": "CVE-2026-49364",
"CWE": null,
"advisories": [
"RHSA-2026:66488",
"RHSA-2026:70229",
"RHSA-2026:66545",
"RHSA-2026:70230",
"RHSA-2026:70228",
"RHSA-2026:67604"
],
"affected_packages": [
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el8eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el9eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el10eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el9eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el10eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el8eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el8eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el10eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el9eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el8eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el10eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el8eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el9eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el10eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el10eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el8eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el9eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el10eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el9eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el9eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el8eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el8eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el7eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el8eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el9eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el10eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el8eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el10eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el9eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el10eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el10eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el9eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el8eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el8eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el9eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el9eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el9eap",
"artemis-server",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el9eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el9eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el9eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el10eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el9eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el9eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el8eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el10eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el10eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el9eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el9eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el9eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el9eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el10eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el8eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el10eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el8eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el10eap",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el10eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el8eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el9eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el7eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el8eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el10eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el8eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el10eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el10eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el8eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el10eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el9eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el8eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el8eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el8eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el7eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el10eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el9eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el10eap",
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el10eap",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el8eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el8eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el10eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el9eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el10eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el10eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el10eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el8eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el8eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el10eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el8eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el8eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el8eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el9eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1el9eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el9eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el8eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el9eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el8eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el9eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el10eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el8eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el8eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el8eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el10eap"
],
"bugzilla": "2478013",
"bugzilla_description": "wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof",
"cvss3_score": "8.0",
"cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-10T05:38:15Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-49364.json",
"severity": "important"
} | — | ||||
| Packages packages | Red Hat | eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el8eap, eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el9eap, eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap, eap8-parsson-0:1.1.9-1.redhat_00001.1.el10eap, eap8-parsson-0:1.1.9-1.redhat_00001.1.el9eap, eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el7eap, eap8-neethi-0:3.2.2-1.redhat_00001.1.el10eap, eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el8eap, eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el8eap, eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el10eap, eap8-log4j-0:2.25.4-1.redhat_00003.1.el9eap, eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap, eap8-xml-security-0:3.0.6-1.redhat_00001.1.el8eap, eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el10eap, eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el8eap, eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el9eap, eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el10eap, eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap, eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el10eap, eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el8eap, eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el9eap, eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el10eap, eap8-slf4j-0:2.0.18-1.redhat_00001.1.el9eap, eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el9eap, eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el8eap, eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el8eap, eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el7eap, eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el7eap, eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el8eap, eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el9eap, eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el10eap, eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el8eap, eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap, eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap, eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el10eap, eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el9eap, eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el10eap, eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el10eap, eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el9eap, eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el8eap, eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el8eap, eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el9eap, eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el9eap, eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el9eap, artemis-server, eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el9eap, eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el9eap, eap8-neethi-0:3.2.2-1.redhat_00001.1.el9eap, eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el10eap, eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el9eap, eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el9eap, eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el8eap, eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el10eap, eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el10eap, eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el9eap, eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el8eap, eap8-xml-security-0:3.0.6-1.redhat_00001.1.el9eap, eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el10eap, eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el10eap, eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el9eap, eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap, eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el9eap, eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap, eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jaxb-0:4.0.7-4.redhat_00001.1.el10eap, eap8-jaxb-0:4.0.7-4.redhat_00001.1.el8eap, eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el8eap, eap8-xml-security-0:3.0.6-1.redhat_00001.1.el10eap, eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el8eap, eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el10eap, eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el10eap, eap8-neethi-0:3.2.2-1.redhat_00001.1.el8eap, eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el9eap, eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el7eap, eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el8eap, eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el7eap, eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el10eap, eap8-slf4j-0:2.0.18-1.redhat_00001.1.el8eap, eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el10eap, eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el10eap, eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el8eap, eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el10eap, eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap, eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el9eap, eap8-parsson-0:1.1.9-1.redhat_00001.1.el8eap, eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el8eap, eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el8eap, eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el7eap, eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el10eap, eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el9eap, eap8-log4j-0:2.25.4-1.redhat_00003.1.el10eap, eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap, eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap, eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el9eap, eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el10eap, eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el8eap, eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el8eap, eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el9eap, eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el10eap, eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el9eap, eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap, eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el10eap, eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el10eap, eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el7eap, eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el10eap, eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el8eap, eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el8eap, eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el9eap, eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el10eap, eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el8eap, eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el8eap, eap8-log4j-0:2.25.4-1.redhat_00003.1.el8eap, eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el9eap, eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el9eap, eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el9eap, eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1el9eap, eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el9eap, eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap, eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el8eap, eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el9eap, eap8-slf4j-0:2.0.18-1.redhat_00001.1.el10eap, eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el8eap, eap8-jaxb-0:4.0.7-4.redhat_00001.1.el9eap, eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el10eap, eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el8eap, eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el7eap, eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el8eap, eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el8eap, eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el10eapreceipt
What the source handed over{
"CVE": "CVE-2026-49364",
"CWE": null,
"advisories": [
"RHSA-2026:66488",
"RHSA-2026:70229",
"RHSA-2026:66545",
"RHSA-2026:70230",
"RHSA-2026:70228",
"RHSA-2026:67604"
],
"affected_packages": [
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el8eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el9eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el10eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el9eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el10eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el8eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el8eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el10eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el9eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el8eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el10eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el8eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el9eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el10eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el10eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el8eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el9eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el10eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el9eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el9eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el8eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el8eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el7eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el8eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el9eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el10eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el8eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el10eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el9eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el10eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el10eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el9eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el8eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el8eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el9eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el9eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el9eap",
"artemis-server",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el9eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el9eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el9eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el10eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el9eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el9eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el8eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el10eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el10eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el9eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el9eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el9eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el9eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el10eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el8eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el10eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el8eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el10eap",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el10eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el8eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el9eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el7eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el8eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el10eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el8eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el10eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el10eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el8eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el10eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el9eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el8eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el8eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el8eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el7eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el10eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el9eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el10eap",
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el10eap",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el8eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el8eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el10eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el9eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el10eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el10eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el10eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el8eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el8eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el10eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el8eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el8eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el8eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el9eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1el9eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el9eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el8eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el9eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el8eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el9eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el10eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el8eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el8eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el8eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el10eap"
],
"bugzilla": "2478013",
"bugzilla_description": "wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof",
"cvss3_score": "8.0",
"cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-10T05:38:15Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-49364.json",
"severity": "important"
} | — | ||||
| Product product | NVD | Apache Artemisreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.artemis:artemis-core-client",
"packageURL": "pkg:maven/org.apache.artemis/artemis-core-client",
"product": "Apache Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.56.0",
"status": "affected",
"version": "2.50.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.artemis:artemis-server",
"packageURL": "pkg:maven/org.apache.artemis/artemis-server",
"product": "Apache Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.56.0",
"status": "affected",
"version": "2.50.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.activemq:artemis-core-client",
"packageURL": "pkg:maven/org.apache.activemq/artemis-core-client",
"product": "Apache ActiveMQ Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.44.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.activemq:artemis-server",
"packageURL": "pkg:maven/org.apache.activemq/artemis-server",
"product": "Apache ActiveMQ Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.44.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B6E3F972-3247-4504-AFD9-833891228040",
"versionEndExcluding": "2.44.0",
"versionStartIncluding": "1.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A41D89AC-2573-4270-9C7C-21D85E1096FE",
"versionEndExcluding": "2.57.0",
"versionStartIncluding": "2.50.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.\n\nThis issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.\n\n\n\nUsers are recommended to upgrade to version 2.57.0, which fixes the issue."
}
],
"id": "CVE-2026-49364",
"lastModified": "2026-09-16T01:10:31.487",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-49364",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T15:54:10.664215Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-10T05:17:01.230",
"references": [
{
"source": "security@apache.org",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"url": "https://lists.apache.org/thread/4qbgcz3k38q30bfbf7hphtomrdc8l8n8"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"url": "http://www.openwall.com/lists/oss-security/2026/09/10/3"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-306"
}
],
"source": "security@apache.org",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2026-49364",
"CWE": null,
"advisories": [
"RHSA-2026:66488",
"RHSA-2026:70229",
"RHSA-2026:66545",
"RHSA-2026:70230",
"RHSA-2026:70228",
"RHSA-2026:67604"
],
"affected_packages": [
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el8eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el9eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el10eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el9eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el10eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el8eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el8eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el10eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el9eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el8eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el10eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el8eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el9eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el10eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el10eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el8eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el9eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el10eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el9eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el9eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el8eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el8eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el7eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el8eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el9eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el10eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el8eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el10eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el9eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el10eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el10eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el9eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el8eap",
"eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el8eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el9eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el9eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el9eap",
"artemis-server",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el9eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el9eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el9eap",
"eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el10eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el9eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el9eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el8eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el10eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el10eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el9eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el9eap",
"eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el9eap",
"eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el9eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el10eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el8eap",
"eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el8eap",
"eap8-xml-security-0:3.0.6-1.redhat_00001.1.el10eap",
"eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el8eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el10eap",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el10eap",
"eap8-neethi-0:3.2.2-1.redhat_00001.1.el8eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el9eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el7eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el8eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el10eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el8eap",
"eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el10eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el10eap",
"eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el8eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el10eap",
"eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el9eap",
"eap8-parsson-0:1.1.9-1.redhat_00001.1.el8eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el8eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el8eap",
"eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el7eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el10eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el9eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el10eap",
"eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap",
"eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el10eap",
"eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el8eap",
"eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el8eap",
"eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el10eap",
"eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el10eap",
"eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el9eap",
"eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el10eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el10eap",
"eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el10eap",
"eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el8eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el8eap",
"eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el9eap",
"eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el10eap",
"eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap",
"eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el8eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el8eap",
"eap8-log4j-0:2.25.4-1.redhat_00003.1.el8eap",
"eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el9eap",
"eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el9eap",
"eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1el9eap",
"eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el9eap",
"eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap",
"eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el8eap",
"eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el9eap",
"eap8-slf4j-0:2.0.18-1.redhat_00001.1.el10eap",
"eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el8eap",
"eap8-jaxb-0:4.0.7-4.redhat_00001.1.el9eap",
"eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el10eap",
"eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el8eap",
"eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el7eap",
"eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el8eap",
"eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el8eap",
"eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el10eap"
],
"bugzilla": "2478013",
"bugzilla_description": "wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof",
"cvss3_score": "8.0",
"cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-10T05:38:15Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-49364.json",
"severity": "important"
} | high | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.artemis:artemis-core-client",
"packageURL": "pkg:maven/org.apache.artemis/artemis-core-client",
"product": "Apache Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.56.0",
"status": "affected",
"version": "2.50.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.artemis:artemis-server",
"packageURL": "pkg:maven/org.apache.artemis/artemis-server",
"product": "Apache Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.56.0",
"status": "affected",
"version": "2.50.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.activemq:artemis-core-client",
"packageURL": "pkg:maven/org.apache.activemq/artemis-core-client",
"product": "Apache ActiveMQ Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.44.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.activemq:artemis-server",
"packageURL": "pkg:maven/org.apache.activemq/artemis-server",
"product": "Apache ActiveMQ Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.44.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B6E3F972-3247-4504-AFD9-833891228040",
"versionEndExcluding": "2.44.0",
"versionStartIncluding": "1.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A41D89AC-2573-4270-9C7C-21D85E1096FE",
"versionEndExcluding": "2.57.0",
"versionStartIncluding": "2.50.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.\n\nThis issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.\n\n\n\nUsers are recommended to upgrade to version 2.57.0, which fixes the issue."
}
],
"id": "CVE-2026-49364",
"lastModified": "2026-09-16T01:10:31.487",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-49364",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T15:54:10.664215Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-10T05:17:01.230",
"references": [
{
"source": "security@apache.org",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"url": "https://lists.apache.org/thread/4qbgcz3k38q30bfbf7hphtomrdc8l8n8"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"url": "http://www.openwall.com/lists/oss-security/2026/09/10/3"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-306"
}
],
"source": "security@apache.org",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | Apache Software Foundationreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.artemis:artemis-core-client",
"packageURL": "pkg:maven/org.apache.artemis/artemis-core-client",
"product": "Apache Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.56.0",
"status": "affected",
"version": "2.50.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.artemis:artemis-server",
"packageURL": "pkg:maven/org.apache.artemis/artemis-server",
"product": "Apache Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.56.0",
"status": "affected",
"version": "2.50.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.activemq:artemis-core-client",
"packageURL": "pkg:maven/org.apache.activemq/artemis-core-client",
"product": "Apache ActiveMQ Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.44.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://repo.maven.apache.org/maven2",
"defaultStatus": "unaffected",
"packageName": "org.apache.activemq:artemis-server",
"packageURL": "pkg:maven/org.apache.activemq/artemis-server",
"product": "Apache ActiveMQ Artemis",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.44.0",
"status": "affected",
"version": "1.0.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B6E3F972-3247-4504-AFD9-833891228040",
"versionEndExcluding": "2.44.0",
"versionStartIncluding": "1.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A41D89AC-2573-4270-9C7C-21D85E1096FE",
"versionEndExcluding": "2.57.0",
"versionStartIncluding": "2.50.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.\n\nThis issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.\n\n\n\nUsers are recommended to upgrade to version 2.57.0, which fixes the issue."
}
],
"id": "CVE-2026-49364",
"lastModified": "2026-09-16T01:10:31.487",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-49364",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-10T15:54:10.664215Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-10T05:17:01.230",
"references": [
{
"source": "security@apache.org",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"url": "https://lists.apache.org/thread/4qbgcz3k38q30bfbf7hphtomrdc8l8n8"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"url": "http://www.openwall.com/lists/oss-security/2026/09/10/3"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-306"
}
],
"source": "security@apache.org",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof zetlyn/cve-redhat · 2026-09-10 | cvss 8 packages eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el8eap, eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el9eap, eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap, eap8-parsson-0:1.1.9-1.redhat_00001.1.el10eap, eap8-parsson-0:1.1.9-1.redhat_00001.1.el9eap, eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el7eap, eap8-neethi-0:3.2.2-1.redhat_00001.1.el10eap, eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el8eap, eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el8eap, eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el10eap, eap8-log4j-0:2.25.4-1.redhat_00003.1.el9eap, eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap, eap8-xml-security-0:3.0.6-1.redhat_00001.1.el8eap, eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el10eap, eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el8eap, eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el9eap, eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el10eap, eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap, eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el10eap, eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el8eap, eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el9eap, eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el10eap, eap8-slf4j-0:2.0.18-1.redhat_00001.1.el9eap, eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el9eap, eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el8eap, eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el8eap, eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el7eap, eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el7eap, eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el8eap, eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el9eap, eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el10eap, eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el8eap, eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap, eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap, eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el10eap, eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el9eap, eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el10eap, eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el10eap, eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el9eap, eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el8eap, eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el8eap, eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el9eap, eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el9eap, eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el9eap, artemis-server, eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el9eap, eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el9eap, eap8-neethi-0:3.2.2-1.redhat_00001.1.el9eap, eap8-jbossws-api-0:3.1.0-1.Final_redhat_00001.1.el10eap, eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el9eap, eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el9eap, eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el8eap, eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el10eap, eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el10eap, eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el9eap, eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el8eap, eap8-xml-security-0:3.0.6-1.redhat_00001.1.el9eap, eap8-jackson-dataformats-text-0:2.18.9-1.redhat_00003.1.el10eap, eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el10eap, eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el9eap, eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap, eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el9eap, eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap, eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jaxb-0:4.0.7-4.redhat_00001.1.el10eap, eap8-jaxb-0:4.0.7-4.redhat_00001.1.el8eap, eap8-httpcomponents-asyncclient-0:4.1.5-5.redhat_00008.1.el8eap, eap8-xml-security-0:3.0.6-1.redhat_00001.1.el10eap, eap8-wildfly-javadocs-0:8.1.1-12.GA_redhat_00048.1.el8eap, eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el10eap, eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el10eap, eap8-neethi-0:3.2.2-1.redhat_00001.1.el8eap, eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el9eap, eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el7eap, eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el8eap, eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el7eap, eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el10eap, eap8-slf4j-0:2.0.18-1.redhat_00001.1.el8eap, eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el10eap, eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el10eap, eap8-hibernate-0:6.6.54-1.Final_redhat_00001.1.el8eap, eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el10eap, eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap, eap8-ws-commons-XmlSchema-0:2.3.2-1.redhat_00001.1.el9eap, eap8-parsson-0:1.1.9-1.redhat_00001.1.el8eap, eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el8eap, eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el8eap, eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el7eap, eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el10eap, eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jboss-remoting-0:5.0.31-1.SP2_redhat_00001.1.el9eap, eap8-log4j-0:2.25.4-1.redhat_00003.1.el10eap, eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap, eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el10eap, eap8-jsf-impl-0:4.0.11-2.SP1_redhat_00001.1.el9eap, eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap, eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el10eap, eap8-undertow-0:2.3.26-2.SP3_redhat_00001.1.el8eap, eap8-eap-product-conf-parent-0:801.8.0-1.GA_redhat_00001.1.el8eap, eap8-jbossws-common-tools-0:2.2.0-1.Final_redhat_00001.1.el9eap, eap8-jbossws-spi-0:5.1.0-1.Final_redhat_00001.1.el10eap, eap8-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jboss-logging-0:3.6.3-1.Final_redhat_00001.1.el9eap, eap8-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap, eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el10eap, eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el10eap, eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el7eap, eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el10eap, eap8-artemis-wildfly-integration-0:2.0.5-1.Final_redhat_00001.1.el8eap, eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el8eap, eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el9eap, eap8-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el10eap, eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap, eap8-jakarta-xml-bind-api-0:4.0.5-1.redhat_00001.1.el8eap, eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1.el8eap, eap8-log4j-0:2.25.4-1.redhat_00003.1.el8eap, eap8-netty-transport-native-epoll-0:4.1.136-1.Final_redhat_00001.1.el9eap, eap8-wildfly-elytron-0:2.6.11-1.Final_redhat_00001.1.el9eap, eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el9eap, eap8-jbossws-jaxws-undertow-httpspi-0:3.0.1-1.Final_redhat_00001.1el9eap, eap8-activemq-artemis-0:2.40.0-8.redhat_00024.1.el9eap, eap8-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap, eap8-netty-0:4.1.136-1.Final_redhat_00001.1.el8eap, eap8-cryptacular-0:1.2.7-1.redhat_00002.1.el9eap, eap8-slf4j-0:2.0.18-1.redhat_00001.1.el10eap, eap8-jaxbintros-0:2.1.0-1.redhat_00001.1.el8eap, eap8-jaxb-0:4.0.7-4.redhat_00001.1.el9eap, eap8-apache-cxf-0:4.1.7-1.SP1_redhat_00001.1.el10eap, eap8-nimbus-jose-jwt-0:9.37.4-1.redhat_00001.1.el8eap, eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el7eap, eap8-bouncycastle-0:1.85.0-1.redhat_00001.1.el8eap, eap8-saaj-impl-0:3.0.6-1.redhat_00001.1.el8eap, eap8-ironjacamar-0:3.0.22-1.Final_redhat_00001.1.el10eap severity important | source |
| An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue. zetlyn/cve-nvd · 2026-09-10 | cvss 9.1 product Apache Artemis status Analyzed vendor Apache Software Foundation | source |