Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-74761
Apache ActiveMQ lets an authenticated client spoof the clientId when removing a durable topic subscription
Technology
Apache ActiveMQ
CVSS Score
7.5 / 10.0
Affected Versions
before 5.19.11; 6.0.0 before 6.3.2 (includes every 6.2.x release)
Upstream Fix
5.19.11 and 6.3.2
Published
September 9, 2026
OSSeva Coverage
Fixed upstream
Is your Apache ActiveMQ deployment affected?
If you're running before 5.19.11; 6.0.0 before 6.3.2 (includes every 6.2.x release), you need this patch. Book a discovery call to get covered.