Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-54475
Apache ActiveMQ temporary destinations can be consumed by another connection
Technology
Apache ActiveMQ
CVSS Score
7.5 / 10.0
Affected Versions
before 5.19.8; 6.0.0 before 6.2.7
Upstream Fix
5.19.8 and 6.2.7
Published
June 30, 2026
OSSeva Coverage
Fixed upstream
Description
Temporary destinations are meant to be private to the connection that created them, but the broker relied on the client to enforce that. A different connection can consume from another connection's temporary destination. Apache rates the issue important; the 7.5 score on NVD is from CISA-ADP.
Is your Apache ActiveMQ deployment affected?
If you're running before 5.19.8; 6.0.0 before 6.2.7, you need this patch. Book a discovery call to get covered.