PT-2026-65464 · Apache · Activemq

CVE-2026-61487

·

Published

2026-07-28

·

Updated

2026-08-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ Broker versions prior to 5.19.9 Apache ActiveMQ Broker versions 6.0.0 through 6.2.7 Apache ActiveMQ All versions prior to 5.19.9 Apache ActiveMQ All versions 6.0.0 through 6.2.7 Apache ActiveMQ versions prior to 5.19.9 Apache ActiveMQ versions 6.0.0 through 6.2.7
Description An authenticated low-privilege user can bypass per-destination write Access Control Lists (ACL) by sending messages to a temporary composite destination. By using a physical name that is a comma-separated composite of real queues, the user can publish messages to any destination in that list. This occurs because the authorization check is bypassed when the composite destination is marked as temporary.
Recommendations Upgrade Apache ActiveMQ Broker to version 5.19.9, 6.2.8, or 6.3.0. Upgrade Apache ActiveMQ All to version 5.19.9, 6.2.8, or 6.3.0. Upgrade Apache ActiveMQ to version 5.19.9, 6.2.8, or 6.3.0.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2026-61487
CVE-2026-61487
OESA-2026-3264
OESA-2026-3265
OESA-2026-3266
OESA-2026-3267

Affected Products

Activemq