PT-2026-45383 · Apache+1 · Activemq+1

·

CVE-2026-49270

·

Published

2026-06-01

·

Updated

2026-07-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ Broker versions prior to 5.19.7 Apache ActiveMQ Broker versions 6.0.0 through 6.2.5 Apache ActiveMQ versions prior to 5.19.7 Apache ActiveMQ versions 6.0.0 through 6.2.5 Apache ActiveMQ All versions prior to 5.19.7 Apache ActiveMQ All versions 6.0.0 through 6.2.5
Description An exposure of sensitive information through metadata occurs when brokers are configured with a network connector where syncDurableSubs is set to true. An unauthenticated attacker can retrieve a list of all durable topic subscriptions in the broker by sending a BrokerInfo command. The broker fails to ensure the connection is authenticated before responding, potentially leaking client identifiers, subscription names, topic destinations, and JMS selector expressions.
Recommendations Upgrade to version 5.19.7 Upgrade to version 6.2.6

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14105
BIT-ACTIVEMQ-2026-49270
CVE-2026-49270
GHSA-HF52-78X8-6W3W
OESA-2026-2723
OESA-2026-2724
OESA-2026-2725

Affected Products

Activemq
Red Os