CVE-2026-61487

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. This issue affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which fixes the issue.
References
Link Resource
https://lists.apache.org/thread/6rwn6cq65dy4lhmsmjf2bxnhbmhkcswz Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/07/27/8 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_all:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_all:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*

History

05 Aug 2026, 18:46

Type Values Removed Values Added
CPE cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq_all:*:*:*:*:*:*:*:*
First Time Apache activemq
Apache
Apache activemq All
Apache activemq Broker
References () https://lists.apache.org/thread/6rwn6cq65dy4lhmsmjf2bxnhbmhkcswz - () https://lists.apache.org/thread/6rwn6cq65dy4lhmsmjf2bxnhbmhkcswz - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/07/27/8 - () http://www.openwall.com/lists/oss-security/2026/07/27/8 - Mailing List, Third Party Advisory

28 Jul 2026, 15:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

28 Jul 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-28 14:16

Updated : 2026-08-05 18:46


NVD link : CVE-2026-61487

Mitre link : CVE-2026-61487

CVE.ORG link : CVE-2026-61487


JSON object : View

Products Affected

apache

  • activemq
  • activemq_all
  • activemq_broker
CWE
CWE-285

Improper Authorization