Improper access control in ActiveMQ - CVE-2026-49270
Published: June 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the OpenWire BrokerInfo handling when processing a BrokerInfo command on a broker with a network connector configured with syncDurableSubs set to true. A remote attacker can send a BrokerInfo command to disclose sensitive information.
The exposed metadata includes durable topic subscription details such as client identifiers, subscription names, topic destinations, and JMS selector expressions.
Affected software
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-49270
activemq - update to 5.19.7-1
activemq-javadoc - update to 5.19.7-1