Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM.
This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/hcjh7kdk4l85tb9ksmvcnkhso1ngj50o | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/06/29/8 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Jul 2026, 18:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://lists.apache.org/thread/hcjh7kdk4l85tb9ksmvcnkhso1ngj50o - Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/06/29/8 - Third Party Advisory | |
| First Time |
Apache activemq
Apache Apache activemq Broker |
|
| CPE | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:* |
30 Jun 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
30 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jun 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-30 11:16
Updated : 2026-07-02 18:43
NVD link : CVE-2026-49434
Mitre link : CVE-2026-49434
CVE.ORG link : CVE-2026-49434
JSON object : View
Products Affected
apache
- activemq
- activemq_broker
CWE
CWE-20
Improper Input Validation
