Description
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms.




An authenticated client can spoof clientId when removing a durable topic subscription.



This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2.



Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.
Published: 2026-09-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized removal of durable subscriptions via client impersonation
Action: Upgrade
AI Analysis

Impact

The flaw is an input validation weakness (CWE‑20) in ActiveMQ’s TopicRegion module that lets an authenticated client disguise its clientId when sending a RemoveSubscription command for a durable topic subscription. By spoiling the identifier, an attacker can delete a subscription belonging to another user, thereby causing that user to lose guaranteed message delivery. This does not provide code execution or elevate privileges; it simply alters subscription state and can disrupt service for other tenants.

Affected Systems

Apache ActiveMQ deployments that use the Broker, the bundled All distribution, or the standalone product are affected when running versions older than 5.19.11 or any 6.x release before 6.3.2. Any instance in those release ranges that accepts authenticated connections is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.5 reflects a moderate‑to‑high risk, requiring only valid credentials and the ability to issue a RemoveSubscription request. The EPSS score of less than 1% indicates that exploitation is unlikely to be widespread, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, an attacker who can authenticate can unobtrusively delete other users’ durable subscriptions, which can be a denial‑of‑service or privacy concern in multi‑tenant environments.

Generated by OpenCVE AI on September 11, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ActiveMQ to version 5.19.11 or 6.3.2, which applies the proper input validation fix.
  • Configure role‑based access controls or broker policies to restrict the RemoveSubscription operation to trusted administrative users only.
  • Audit existing durable subscriptions for unexpected deletions and monitor broker logs for suspicious RemoveSubscription activity to detect abuse.

Generated by OpenCVE AI on September 11, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_all:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq
Apache activemq All
Apache activemq Broker
Vendors & Products Apache
Apache activemq
Apache activemq All
Apache activemq Broker

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.
Title Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Weaknesses CWE-20
References

Subscriptions

Apache Activemq Activemq All Activemq Broker
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T18:00:51.191Z

Reserved: 2026-08-15T13:53:34.221Z

Link: CVE-2026-74761

cve-icon Vulnrichment

Updated: 2026-09-09T11:11:01.680Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T12:17:13.040

Modified: 2026-09-18T14:37:42.543

Link: CVE-2026-74761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:30:14Z

Weaknesses
  • CWE-20

    Improper Input Validation