Improper Input Validation in Apache ActiveMQ Products
CVE-2026-74761

Currently unrated

What is CVE-2026-74761?

A vulnerability exists in Apache ActiveMQ where improper input validation allows authenticated clients to spoof the clientId while removing a durable topic subscription. This issue impacts several versions of Apache ActiveMQ Broker and its variants, necessitating users to upgrade to version 6.3.2 or 5.19.11 to mitigate the risk. Failure to address this could lead to unauthorized access and manipulation of subscription management.

Affected Version(s)

Apache ActiveMQ 6.0.0 < 6.3.2

Apache ActiveMQ 0 < 5.19.11

Apache ActiveMQ All 6.0.0 < 6.3.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wanxin Yin (yaklang.io)
.