CVE-2026-49270
published 2026-06-01CVE-2026-49270: Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured…
PriorityP336medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.33%
25.1th percentile
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | < 5.19.7 | 5.19.7 |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | >= 6.0.0 < 6.2.6 | 6.2.6 |
| apache | activemq_broker | < 5.19.7 | 5.19.7 |
| apache | activemq_broker | — | — |
| apache | activemq_broker | — | — |
| apache | activemq_broker | >= 6.0.0 < 6.2.6 | 6.2.6 |
| apache_software_foundation | apache_activemq | >= 5.19.7 < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq | >= 6.2.6 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq_all | >= 5.19.7 < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq_all | >= 6.2.6 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq_broker | >= 5.19.7 < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq_broker | >= 6.2.6 < 6.2.7 | 6.2.7 |
| candlepinproject | candlepin | — | — |
| log4j_2 | log4j | — | — |
| satellite_el8 | candlepin | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
ghsa_unreviewed·2026-06-30·CVSS 5.9
CVE-2026-50750 [MEDIUM] CWE-400 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM.
This issue affects Apache ActiveMQ Broker: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ All: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7.
Users are recommended to upgrade to version 6.2.7, which fixes the issue.
VulDB
Apache ActiveMQ BrokerInfo privilege escalation (Nessus ID 318668)
vuldb·2026-06-05·CVSS 5.9
CVE-2026-49270 [MEDIUM] Apache ActiveMQ BrokerInfo privilege escalation (Nessus ID 318668)
A vulnerability was found in Apache ActiveMQ. It has been rated as problematic. Affected is an unknown function of the component BrokerInfo Handler. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2026-49270. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
ghsa_unreviewed·2026-06-01
CVE-2026-49270 [MEDIUM] CWE-1230 Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to vers
GHSA
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability
ghsa·2026-06-01
CVE-2026-49270 [MEDIUM] CWE-1230 Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before
Red Hat
activemq: Apache ActiveMQ: Denial of Service via repeated BrokerInfo commands
vendor_redhat·2026-06-30·CVSS 5.9
CVE-2026-50750 [MEDIUM] CWE-770 activemq: Apache ActiveMQ: Denial of Service via repeated BrokerInfo commands
activemq: Apache ActiveMQ: Denial of Service via repeated BrokerInfo commands
A flaw was found in Apache ActiveMQ. An unauthenticated remote attacker can exploit this vulnerability by repeatedly sending BrokerInfo commands without corresponding ConnectionInfo commands. This can lead to an Out of Memory condition, causing the broker to crash and resulting in a Denial of Service.
Statement: Red Hat products that include Apache ActiveMQ classic components ship versions prior to 5.19.7 (5.x line) and prior to 6.2.6 (6.x line). The vulnerable code was introduced as a regression in versions 5.19.7 and 6.2.6 while fixing CVE-2026-49270, and is not present in the versions shipped by Red Hat. Products shipping Apache ActiveMQ Artemis are not affected as Artemis is a separate codebase.
Mitigation
Red Hat
apache-activemq-broker: apache-activemq: apache-activemq-all: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command
vendor_redhat·2026-06-01·CVSS 5.9
CVE-2026-49270 [MEDIUM] CWE-306 apache-activemq-broker: apache-activemq: apache-activemq-all: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command
apache-activemq-broker: apache-activemq: apache-activemq-all: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: b
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-50750 activemq: Apache ActiveMQ: Denial of Service via repeated BrokerInfo commands
bugzilla·2026-06-30·CVSS 5.9
CVE-2026-50750 [MEDIUM] CVE-2026-50750 activemq: Apache ActiveMQ: Denial of Service via repeated BrokerInfo commands
CVE-2026-50750 activemq: Apache ActiveMQ: Denial of Service via repeated BrokerInfo commands
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM.
This issue affects Apache ActiveMQ Broker: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ All: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7.
Users are recommended to upgrade to version 6.2.7, which fixes the issue.
Bugzilla
CVE-2026-49270 activemq-cpp: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command [fedora-all]
bugzilla·2026-06-30·CVSS 5.9
CVE-2026-49270 [MEDIUM] CVE-2026-49270 activemq-cpp: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command [fedora-all]
CVE-2026-49270 activemq-cpp: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a Bro
Bugzilla
CVE-2026-49270 activemq-cpp: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command [epel-all]
bugzilla·2026-06-30·CVSS 5.9
CVE-2026-49270 [MEDIUM] CVE-2026-49270 activemq-cpp: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command [epel-all]
CVE-2026-49270 activemq-cpp: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a Broke
Bugzilla
CVE-2026-49270 apache-activemq-broker: apache-activemq: apache-activemq-all: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command
bugzilla·2026-06-09·CVSS 5.9
CVE-2026-49270 [MEDIUM] CVE-2026-49270 apache-activemq-broker: apache-activemq: apache-activemq-all: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command
CVE-2026-49270 apache-activemq-broker: apache-activemq: apache-activemq-all: Apache ActiveMQ: Information disclosure via unauthenticated BrokerInfo command
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Ap
2026-06-01
Published