Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-54475

Apache ActiveMQ temporary destinations can be consumed by another connection

Technology

Apache ActiveMQ

CVSS Score

7.5 / 10.0

Affected Versions

before 5.19.8; 6.0.0 before 6.2.7

Upstream Fix

5.19.8 and 6.2.7

Published

June 30, 2026

OSSeva Coverage

Fixed upstream

Description

Temporary destinations are meant to be private to the connection that created them, but the broker relied on the client to enforce that. A different connection can consume from another connection's temporary destination. Apache rates the issue important; the 7.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache ActiveMQ deployment affected?

If you're running before 5.19.8; 6.0.0 before 6.2.7, you need this patch. Book a discovery call to get covered.