CVE-2026-54475 Details
Description
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to consume from another connection's temporary destination. This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7, which fixes the issue.
A missing authorization vulnerability exists in Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ Classic. Temporary destinations in Apache ActiveMQ Classic are meant to be isolated to the connection that created them. However, this isolation can be compromised because the check is only performed on the client side. As a result, one connection can consume messages from another connection's temporary destination. This vulnerability affects Apache ActiveMQ Broker versions prior to 5.19.8 and 6.0.0 prior to 6.2.7, as well as Apache ActiveMQ All and Apache ActiveMQ Classic in the same version ranges.
Users are advised to upgrade to Apache ActiveMQ version 6.2.7 or later, or to Apache ActiveMQ Broker version 5.19.8 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/29/15 | CVE | Third Party Advisory |
| https://lists.apache.org/thread/85f3q7mkh71y7qwyn6wvgw0bw4jl06ys | [email protected] | Vendor AdvisoryMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | < 5.19.8 >= 6.0.0, < 6.2.7 |
CPE
Remediation
| |
| apache activemq broker | < 5.19.8 >= 6.0.0, < 6.2.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | CVE Modified | CVE |
| Jun 30, 2026 | New CVE Received | [email protected] |