7.5
CVE-2026-74761
- EPSS 0.39%
- Veröffentlicht 09.09.2026 11:10:16
- Zuletzt bearbeitet 18.09.2026 14:37:42
- Erkennungen
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Activemq All Version < 5.19.11
Apache ≫ Activemq All Version >= 6.0.0 < 6.3.2
Apache ≫ Activemq Broker Version < 5.19.11
Apache ≫ Activemq Broker Version >= 6.2.0 < 6.3.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.324 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://lists.apache.org/thread/n9md06jo7ccqmj2mntx4kpcl2d5xqntz
http://www.openwall.com/lists/oss-security/2026/09/08/12