CVE-2026-49434 Details
Description
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM. This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
A vulnerability exists in Apache ActiveMQ Broker, Apache ActiveMQ, and Apache ActiveMQ All, all versions prior to 5.19.8 and ActiveMQ 6.0.0 prior to 6.2.7. This vulnerability arises from improper input validation, allowing an attacker with access to publish or modify LDAP entries that align with the configured searchBase and searchFilter to instantiate denied transports within the broker's JVM. Exploitation of this vulnerability could enable the attacker to retrieve a URL and initiate a second BrokerService within the same JVM.
Users are advised to upgrade to Apache ActiveMQ version 6.2.7 or 5.19.8, both of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/29/8 | CVE | Third Party Advisory |
| https://lists.apache.org/thread/hcjh7kdk4l85tb9ksmvcnkhso1ngj50o | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | < 5.19.8 >= 6.0.0, < 6.2.7 |
CPE
Remediation
| |
| apache activemq broker | < 5.19.8 >= 6.0.0, < 6.2.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | CVE Modified | CVE |
| Jun 30, 2026 | New CVE Received | [email protected] |