Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-74761

Apache ActiveMQ lets an authenticated client spoof the clientId when removing a durable topic subscription

Technology

Apache ActiveMQ

CVSS Score

7.5 / 10.0

Affected Versions

before 5.19.11; 6.0.0 before 6.3.2 (includes every 6.2.x release)

Upstream Fix

5.19.11 and 6.3.2

Published

September 9, 2026

OSSeva Coverage

Fixed upstream

Description

Improper input validation in TopicRegion lets an authenticated client give another client's clientId when it removes a durable topic subscription. Apache rates the issue moderate; the 7.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache ActiveMQ deployment affected?

If you're running before 5.19.11; 6.0.0 before 6.3.2 (includes every 6.2.x release), you need this patch. Book a discovery call to get covered.