CVE-2026-49434

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM. This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*

History

02 Jul 2026, 18:43

Type Values Removed Values Added
References () https://lists.apache.org/thread/hcjh7kdk4l85tb9ksmvcnkhso1ngj50o - () https://lists.apache.org/thread/hcjh7kdk4l85tb9ksmvcnkhso1ngj50o - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/06/29/8 - () http://www.openwall.com/lists/oss-security/2026/06/29/8 - Third Party Advisory
First Time Apache activemq
Apache
Apache activemq Broker
CPE cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*

30 Jun 2026, 13:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

30 Jun 2026, 12:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/06/29/8 -

30 Jun 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 11:16

Updated : 2026-07-02 18:43


NVD link : CVE-2026-49434

Mitre link : CVE-2026-49434

CVE.ORG link : CVE-2026-49434


JSON object : View

Products Affected

apache

  • activemq
  • activemq_broker
CWE
CWE-20

Improper Input Validation