Improper access control in ActiveMQ - CVE-2026-49270
Published: June 4, 2026
ActiveMQ
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the OpenWire BrokerInfo handling when processing a BrokerInfo command on a broker with a network connector configured with syncDurableSubs set to true. A remote attacker can send a BrokerInfo command to disclose sensitive information.
The exposed metadata includes durable topic subscription details such as client identifiers, subscription names, topic destinations, and JMS selector expressions.