CVE-2026-49270 Details
Description
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
A vulnerability allowing the exposure of sensitive information through metadata has been identified in Apache ActiveMQ Broker, ActiveMQ, and ActiveMQ All. This issue affects brokers configured with a network connector that has syncDurableSubs set to true. An unauthenticated attacker can exploit this vulnerability by sending a BrokerInfo command, which prompts the broker to disclose a list of all durable topic subscriptions. The response includes client identifiers, subscription names, topic destinations, and JMS selector expressions. The broker fails to authenticate the connection before responding, leading to unauthorized information disclosure. This vulnerability exists in Apache ActiveMQ Broker versions prior to 5.19.7 and from 6.0.0 prior to 6.2.6, as well as in Apache ActiveMQ and Apache ActiveMQ All versions within the same ranges.
Users are advised to upgrade to Apache ActiveMQ versions 6.2.6 or 5.19.7, both of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/31/22 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/k3233c1x506z3w7x4z0dqvd86d4v2fr2 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1230 | Exposure of Sensitive Information Through Metadata | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | < 5.19.7 >= 6.0.0, < 6.2.6 |
CPE
Remediation
| |
| apache activemq broker | < 5.19.7 >= 6.0.0, < 6.2.6 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |
| Jun 1, 2026 | CVE Modified | CVE |