7.5

CVE-2026-74761

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms.




An authenticated client can spoof clientId when removing a durable topic subscription.



This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2.



Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Activemq Version < 5.19.11
Apache ≫ Activemq Version >= 6.0.0 < 6.3.2
Apache ≫ Activemq All Version < 5.19.11
Apache ≫ Activemq All Version >= 6.0.0 < 6.3.2
Apache ≫ Activemq Broker Version < 5.19.11
Apache ≫ Activemq Broker Version >= 6.2.0 < 6.3.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.324
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://lists.apache.org/thread/n9md06jo7ccqmj2mntx4kpcl2d5xqntz
Vendor Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2026/09/08/12
Mailing List