Improper access control in ActiveMQ - CVE-2026-49270

 

Improper access control in ActiveMQ - CVE-2026-49270

Published: June 4, 2026


Vulnerability identifier: #VU133393
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49270
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the OpenWire BrokerInfo handling when processing a BrokerInfo command on a broker with a network connector configured with syncDurableSubs set to true. A remote attacker can send a BrokerInfo command to disclose sensitive information.

The exposed metadata includes durable topic subscription details such as client identifiers, subscription names, topic destinations, and JMS selector expressions.


Affected software

ActiveMQ
openEuler
activemq
activemq-javadoc

How to mitigate CVE-2026-49270

Install security update from vendor's website.

ActiveMQ - addressed in versions 5.19.7, 6.2.6
activemq - update to 5.19.7-1
activemq-javadoc - update to 5.19.7-1

External References

Related Security Bulletins