SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-74761

HIGH · CVSS 7.5 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Improper input validation in the TopicRegion component of Apache ActiveMQ allows authenticated clients to spoof the clientId when removing durable topic subscriptions, potentially leading to unauthorized access or manipulation of message subscriptions. This vulnerability affects versions prior to 5.19.11 and from 6.0.0 before 6.3.2 across all platforms. Organizations using affected versions should prioritize upgrading to version 6.3.2 or 5.19.11 to mitigate this risk.

CVE
CVE-2026-74761
Severity
HIGH
CVSS
7.5
EPSS
0.39%
Apache

Original NVD Description

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ AllĀ on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.