Improper Authorization in ActiveMQ - CVE-2026-61487
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization and publish messages to unauthorized destinations.
The vulnerability exists due to improper authorization in ActiveMQ destination authorization handling when sending to a temporary composite destination whose physical name is a comma-separated composite of real queues. A remote user can send a message to a crafted temporary composite destination to bypass authorization and publish messages to unauthorized destinations.
The issue affects per-destination write ACL enforcement for temporary composite destinations.
Affected software
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-61487
activemq - update to 5.19.9-1
activemq-javadoc - update to 5.19.9-1