CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Apache ActiveMQ CVE-2026-74761: moderate clientId spoofing in RemoveSubscription handling, affecting Broker, All and apache-activemq, fixed in 6.3.2 and 5.19.11.
The Apache ActiveMQ team disclosed CVE-2026-74761, a moderate-severity spoofing issue in the handling of RemoveSubscription clientId. Affected components include ActiveMQ Broker (activemq-broker), ActiveMQ All (activemq-all) and Apache ActiveMQ in versions 6.0.0 before 6.3.2 and 5.x before 5.19.11. The flaw could allow a client to spoof another client's clientId when removing subscriptions. Users should upgrade to the 6.3.2 or 5.19.11 release lines or later.
- CVE-2026-74761 rated moderate by the Apache ActiveMQ team
- Affects activemq-broker, activemq-all and apache-activemq distributions
- Patched releases include 6.3.2 and 5.19.11
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-74761 | Improper input validation in Apache ActiveMQ allows clientId spoofing Apache ActiveMQ contains an improper input validation flaw (CWE-20) in the TopicRegion component that manages durable topic subscriptions, affecting all platforms. An authenticated client can spoof another client's clientId when sending a remove-subscription request, causing the broker to delete a durable topic subscription that belongs to a different client. An attacker with valid broker credentials can thereby disrupt other clients' message delivery, since removing a durable subscription can make affected subscribers stop receiving topic messages; the issue is a spoofing/integrity and limited-availability problem, not remote code execution. Users of any of the three distributions (Apache ActiveMQ, ActiveMQ Broker, ActiveMQ All) on versions before 5.19.11 or 6.x from 6.0.0 before 6.3.2 are affected, particularly deployments that accept connections from third-party or multi-tenant authenticated clients. No public proof-of-concept or in-the-wild exploitation is known, the issue is not in CISA KEV, and CVSS scoring is still pending. Do: Upgrade to Apache ActiveMQ 5.19.11 on the 5.x line or 6.3.2 on the 6.x line, covering the ActiveMQ, ActiveMQ Broker, and ActiveMQ All distributions. Until patched, restrict broker access to trusted authenticated clients and review which clients are permitted to remove durable topic subscriptions. With no known public PoC or in-the-wild exploitation, this can be prioritized within normal patch cycles unless brokers expose multi-tenant or third-party clients. | 7.5 | <1% |
| largetens of thousands of internet-exposed ActiveMQ brokers, plus many more internal enterprise deployments |
Posted by Matt Pavlovich on Sep 08 Severity: moderate Affected versions: - Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) 6.0.0 before 6.3.2 - Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) before 5.19.11 - Apache ActiveMQ All (org.apache.activemq:activemq-all) 6.0.0 before 6.3.2 - Apache ActiveMQ All (org.apache.activemq:activemq-all) before 5.19.11 - Apache ActiveMQ (org.apache.activemq:apache-activemq) 6.0.0 before 6.3.2 - Apache ActiveMQ...
This source does not provide full text. Read it at seclists.org.