CVE-2026-61487 Details
Description
Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. This issue affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which fixes the issue.
A vulnerability allowing authorization bypass has been identified in Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ. This issue arises from improper authorization handling, where an authenticated low-privilege user can bypass write access control lists (ACLs) on a per-destination basis. The vulnerability is exploited by sending messages to a temporary composite destination, which is a comma-separated combination of real queues. Since the composite destination is temporary, the usual authorization checks are bypassed, allowing messages to be published to any queue in the list without the necessary permissions. This vulnerability affects Apache ActiveMQ Broker versions prior to 5.19.9 and from 6.0.0 prior to 6.2.8, as well as Apache ActiveMQ All and Apache ActiveMQ versions within the same ranges.
Users are advised to upgrade to Apache ActiveMQ versions 5.19.9, 6.2.8, or 6.3.0, all of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/27/8 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/6rwn6cq65dy4lhmsmjf2bxnhbmhkcswz | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | < 5.19.9 >= 6.0.0, < 6.2.8 |
CPE
Remediation
| |
| apache activemq all | < 5.19.9 >= 6.0.0, < 6.2.8 |
CPE
Remediation
| |
| apache activemq broker | < 5.19.9 >= 6.0.0, < 6.2.8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | Initial Analysis | [email protected] |
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | New CVE Received | [email protected] |
| Jul 28, 2026 | CVE Modified | CVE |