Improper Input Validation in Apache ActiveMQ Products
CVE-2026-74761
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-74761?
A vulnerability exists in Apache ActiveMQ where improper input validation allows authenticated clients to spoof the clientId while removing a durable topic subscription. This issue impacts several versions of Apache ActiveMQ Broker and its variants, necessitating users to upgrade to version 6.3.2 or 5.19.11 to mitigate the risk. Failure to address this could lead to unauthorized access and manipulation of subscription management.
Affected Version(s)
Apache ActiveMQ 6.0.0 < 6.3.2
Apache ActiveMQ 0 < 5.19.11
Apache ActiveMQ All 6.0.0 < 6.3.2