ZeroHour

CVE-2026-74761

large

Improper input validation in Apache ActiveMQ allows clientId spoofing

CVSS 3.1
7.5 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Apache ActiveMQ contains an improper input validation flaw (CWE-20) in the TopicRegion component that manages durable topic subscriptions, affecting all platforms. An authenticated client can spoof another client's clientId when sending a remove-subscription request, causing the broker to delete a durable topic subscription that belongs to a different client. An attacker with valid broker credentials can thereby disrupt other clients' message delivery, since removing a durable subscription can make affected subscribers stop receiving topic messages; the issue is a spoofing/integrity and limited-availability problem, not remote code execution. Users of any of the three distributions (Apache ActiveMQ, ActiveMQ Broker, ActiveMQ All) on versions before 5.19.11 or 6.x from 6.0.0 before 6.3.2 are affected, particularly deployments that accept connections from third-party or multi-tenant authenticated clients. No public proof-of-concept or in-the-wild exploitation is known, the issue is not in CISA KEV, and CVSS scoring is still pending.

What to do: Upgrade to Apache ActiveMQ 5.19.11 on the 5.x line or 6.3.2 on the 6.x line, covering the ActiveMQ, ActiveMQ Broker, and ActiveMQ All distributions. Until patched, restrict broker access to trusted authenticated clients and review which clients are permitted to remove durable topic subscriptions. With no known public PoC or in-the-wild exploitation, this can be prioritized within normal patch cycles unless brokers expose multi-tenant or third-party clients.

Affected
Apache ActiveMQbefore 5.19.11; from 6.0.0 before 6.3.2 (fixed in 5.19.11 or 6.3.2)
Apache ActiveMQ Brokerbefore 5.19.11; from 6.0.0 before 6.3.2 (fixed in 5.19.11 or 6.3.2)
Apache ActiveMQ Allbefore 5.19.11; from 6.0.0 before 6.3.2 (fixed in 5.19.11 or 6.3.2)
Estimated exposure
largetens of thousands of internet-exposed ActiveMQ brokers, plus many more internal enterprise deployments — ActiveMQ is among the most widely deployed open-source JMS brokers and public internet scans index on the order of tens of thousands of exposed instances, though this flaw only matters where untrusted clients hold valid broker credentials.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.

Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId

Apache ActiveMQ CVE-2026-74761: moderate clientId spoofing in RemoveSubscription handling, affecting Broker, All and apache-activemq, fixed in 6.3.2 and 5.19.11.

The Apache ActiveMQ team disclosed CVE-2026-74761, a moderate-severity spoofing issue in the handling of RemoveSubscription clientId. Affected components include ActiveMQ Broker (activemq-broker), ActiveMQ All (activemq-all) and Apache ActiveMQ in versions 6.0.0 before 6.3.2 and 5.x before 5.19.11. The flaw could allow a client to spoof another client's clientId when removing subscriptions. Users should upgrade to the 6.3.2 or 5.19.11 release lines or later.

oss-security · 7d agoVulnerabilityCVE-2026-747611