{
  "threat_severity" : "Important",
  "public_date" : "2026-09-10T05:38:15Z",
  "bugzilla" : {
    "description" : "wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof",
    "id" : "2478013",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2478013"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.0",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "details" : [ "An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.\nThis issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.\nUsers are recommended to upgrade to version 2.57.0, which fixes the issue.", "Artemis and JGroups lack of access controls in certain situations can allow an attacker to spoof a password request in JGroups and subsequently gain access to the cluster. This allows the attacker manage-level authority for provided messaging and queue operations." ],
  "affected_release" : [ {
    "product_name" : "Red Hat AMQ Broker 7.13.6",
    "release_date" : "2026-09-10T00:00:00Z",
    "advisory" : "RHSA-2026:66545",
    "cpe" : "cpe:/a:redhat:amq_broker:7.13",
    "package" : "artemis-server"
  }, {
    "product_name" : "Red Hat AMQ Broker 7.14.1",
    "release_date" : "2026-09-10T00:00:00Z",
    "advisory" : "RHSA-2026:66488",
    "cpe" : "cpe:/a:redhat:amq_broker:7.14",
    "package" : "artemis-server"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Apache Camel 4 for Quarkus 3",
    "fix_state" : "Not affected",
    "package_name" : "jgroups",
    "cpe" : "cpe:/a:redhat:camel_quarkus:3"
  }, {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 4",
    "fix_state" : "Not affected",
    "package_name" : "artemis-server",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:4"
  }, {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 4",
    "fix_state" : "Not affected",
    "package_name" : "jgroups",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:4"
  }, {
    "product_name" : "Red Hat Build of Keycloak",
    "fix_state" : "Not affected",
    "package_name" : "jgroups",
    "cpe" : "cpe:/a:redhat:build_keycloak:"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Affected",
    "package_name" : "artemis-server",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Affected",
    "package_name" : "jgroups",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Affected",
    "package_name" : "wildfly-messaging-activemq-subsystem",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Affected",
    "package_name" : "artemis-server",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Affected",
    "package_name" : "jgroups",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Affected",
    "package_name" : "wildfly-messaging-activemq-subsystem",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-49364\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-49364" ],
  "name" : "CVE-2026-49364",
  "csaw" : false
}