
CVE-2026-32642: Apache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permission https://www.openwall.com/lists/oss-security/2026/03/20/2 whereas the attempt to create the non-durable subscription should instead fail since the user is not authorized
Post summary
The post notes a privilege‑bypass flaw in Apache Artemis that allows automatic creation of temporary addresses, but provides no PoC, exploit code, active‑exploitation evidence, or patch details.



