Threat Advisory

Apache ActiveMQ Flaw Lets Low-Priority Users Bypass Write Permissions

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Apache ActiveMQ versions Both issues hit ActiveMQ Broker, ActiveMQ All, and core ActiveMQ have been identified in Apache ActiveMQ, affecting versions prior to 5.19.9 and between 6.0.0 through 6.2.7, including the activemq-amqp package. The overall risk/impact is high as these flaws can lead to broken access control, trust issues across connected apps, and denial-of-service attacks.

CVE-2026-61487 (CVSS 4.3 - Medium): A low-privilege user can bypass write permissions on protected queues by targeting a temporary composite destination with its physical name listing several real queues separated by commas.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Apache ActiveMQ versions Both issues hit ActiveMQ Broker, ActiveMQ All, and core ActiveMQ have been identified in Apache ActiveMQ, affecting versions prior to 5.19.9 and between 6.0.0 through 6.2.7, including the activemq-amqp package. The overall risk/impact is high as these flaws can lead to broken access control, trust issues across connected apps, and denial-of-service attacks.

CVE-2026-61487 (CVSS 4.3 - Medium): A low-privilege user can bypass write permissions on protected queues by targeting a temporary composite destination with its physical name listing several real queues separated by commas.[emaillocker id="1283"]

CVE-2026-59878 (CVSS 7.5 - High): A remote, unauthenticated peer can crash AMQP connections and starve the broker by sending a frame with a bad size value to an exposed AMQP NIO connector. These vulnerabilities collectively present a significant risk to administrators who have not patched their systems. These vulnerabilities collectively present a significant risk to administrators who have not patched their systems.

These vulnerabilities collectively present a significant risk to administrators who have not patched their systems.

RECOMMENDATION:

We recommend you to update Apache ActiveMQ to version 5.19.9, or 6.2.8 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu