Improper Authorization Vulnerability in Apache ActiveMQ Products
CVE-2026-61487
6.5MEDIUM
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 28 July 2026
What is CVE-2026-61487?
An improper authorization vulnerability exists in Apache ActiveMQ products, allowing low-privilege authenticated users to bypass write access control lists (ACLs). By exploiting this flaw, malicious users can publish messages to destinations included in a comma-separated composite name of real queues, without the required permissions. The issue primarily arises from the authorization checks being skipped for temporary composite destinations. This affects various versions of Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ, necessitating users to update to the recommended versions 5.19.9, 6.2.8, or 6.3.0 to mitigate the risk.
Affected Version(s)
Apache ActiveMQ 0 < 5.19.9
Apache ActiveMQ 6.0.0 < 6.2.8
Apache ActiveMQ All 0 < 5.19.9