Authorization Bypass Vulnerability in Apache ActiveMQ Products
CVE-2026-54475
7.5HIGH
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 30 June 2026
What is CVE-2026-54475?
A missing authorization vulnerability in Apache ActiveMQ allows connections to potentially access temporary destinations created by other connections. This flaw arises due to a lack of server-side validation for the isolation of temporary destinations, which can lead to unauthorized data access. Users should upgrade to version 6.2.7 or later to mitigate this risk and ensure proper access controls are enforced.
Affected Version(s)
Apache ActiveMQ 0 < 5.19.8
Apache ActiveMQ 6.0.0 < 6.2.7
Apache ActiveMQ All 0 < 5.19.8