Description
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.

An authenticated low-privilege user can bypass a per-destination
write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a
comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary.
This issue affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8.

Users are recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which fixes the issue.
Published: 2026-07-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated low‑privilege user can send messages to a temporary composite destination whose physical name is a comma‑separated list of real queues. The broker mistakenly treats such destinations as temporary and skips the per‑destination write ACL check, enabling the user to publish to any queue in the list without proper authorization. This flaw permits unauthorized data publication, which can lead to data leakage, tampering, or service disruption.

Affected Systems

Apache ActiveMQ, including the Broker and All distributions, are affected. Versions before 5.19.9 and all 6.0.0 releases before 6.2.8 contain the vulnerability; the fix is included in 5.19.9, 6.2.8, and 6.3.0.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog. Bypassing the ACL requires an authenticated low‑privilege connection to the broker, making the attack vector an authenticated local or remote user with basic permissions. No arbitrary code execution is possible, but the ability to send messages to arbitrary destinations can still compromise confidentiality and integrity of data transmitted through those queues.

Generated by OpenCVE AI on August 3, 2026 at 14:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the broker to version 5.19.9, 6.2.8, or 6.3.0 to apply the vendor‑provided fix.
  • If an upgrade is not immediately possible, restrict or disable the use of temporary composite destinations for low‑privilege users and enforce strict ACLs that prevent write access to all destinations in the composite list.
  • Continuously monitor broker logs for suspicious message publication activity and verify that ACL enforcement behaves as expected.

Generated by OpenCVE AI on August 3, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq
Apache activemq All
Apache activemq Broker
Vendors & Products Apache
Apache activemq
Apache activemq All
Apache activemq Broker

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. This issue affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which fixes the issue.
Title Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Apache Activemq Activemq All Activemq Broker
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-28T14:07:13.139Z

Reserved: 2026-07-10T12:48:59.563Z

Link: CVE-2026-61487

cve-icon Vulnrichment

Updated: 2026-07-28T13:37:51.068Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T14:16:38.453

Modified: 2026-08-05T18:46:33.780

Link: CVE-2026-61487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:00:15Z

Weaknesses