Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57967

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

in Apache Artemis, the REATTACH_SESSION handler performs zero authentication — it looks up the session by name only and calls transferConnection() unconditionally, migrating the authenticated session to the attacker's connection. The hijacked cluster-bridge session inherits full broker-management authority (message injection, topology manipulation, journal access)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7artemis-serverAffected
Red Hat JBoss Enterprise Application Platform 8artemis-serverAffected
Red Hat JBoss Enterprise Application Platform Expansion Packartemis-serverAffected
Red Hat AMQ Broker 7.13.6artemis-serverFixedRHSA-2026:6654510.09.2026
Red Hat AMQ Broker 7.14.1artemis-serverFixedRHSA-2026:6648810.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2480638artemis-server: Apache Artemis — session hijack via missing authentication

EPSS

Процентиль: 45%
0.00551
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
7 дней назад

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

CVSS3: 9.8
github
7 дней назад

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

EPSS

Процентиль: 45%
0.00551
Низкий

7.4 High

CVSS3