{"id":"GHSA-f4gc-mwrg-q36r","summary":"Apache Artemis: Unauthorized Temporary Address Creation via OpenWire Protocol","details":"Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the \"createDurableQueue\" permission but does not have the \"createAddress\" permission and address auto-creation is disabled. In this circumstance, a temporary address will be created whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized to create the corresponding address. When the OpenWire connection is closed the address is removed.\n\nThis issue affects Apache Artemis: from 2.50.0 through 2.52.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0.\n\nUsers are recommended to upgrade to version 2.53.0, which fixes the issue.","aliases":["CVE-2026-32642"],"modified":"2026-03-26T17:41:21.726660Z","published":"2026-03-24T09:30:31Z","database_specific":{"github_reviewed_at":"2026-03-26T17:26:29Z","nvd_published_at":"2026-03-24T08:16:01Z","cwe_ids":["CWE-863"],"severity":"LOW","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32642"},{"type":"PACKAGE","url":"https://github.com/apache/artemis"},{"type":"WEB","url":"https://lists.apache.org/thread/4wlrp31ngq2yb54sf4kjb3bl41t4xgtp"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/03/20/2"}],"affected":[{"package":{"name":"org.apache.artemis:artemis-openwire-protocol","ecosystem":"Maven","purl":"pkg:maven/org.apache.artemis/artemis-openwire-protocol"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.50.0"},{"fixed":"2.53.0"}]}],"versions":["2.50.0","2.51.0","2.52.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-f4gc-mwrg-q36r/GHSA-f4gc-mwrg-q36r.json"}},{"package":{"name":"org.apache.activemq:artemis-openwire-protocol","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/artemis-openwire-protocol"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.53.0"}]}],"versions":["2.0.0","2.1.0","2.10.0","2.10.1","2.11.0","2.12.0","2.13.0","2.14.0","2.15.0","2.16.0","2.17.0","2.18.0","2.19.0","2.19.1","2.2.0","2.20.0","2.21.0","2.22.0","2.23.0","2.23.1","2.24.0","2.25.0","2.26.0","2.27.0","2.27.1","2.28.0","2.29.0","2.3.0","2.30.0","2.31.0","2.31.1","2.31.2","2.32.0","2.33.0","2.34.0","2.35.0","2.36.0","2.37.0","2.38.0","2.39.0","2.4.0","2.40.0","2.41.0","2.42.0","2.43.0","2.44.0","2.5.0","2.50.0","2.51.0","2.52.0","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.7.0","2.8.0","2.8.1","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-f4gc-mwrg-q36r/GHSA-f4gc-mwrg-q36r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}