CVE-2026-49434
published 2026-06-30CVE-2026-49434: Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.66%
47.4th percentile
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM.
This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | < 5.19.8 | 5.19.8 |
| apache | activemq | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache | activemq_broker | < 5.19.8 | 5.19.8 |
| apache | activemq_broker | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq_all | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq_all | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq_broker | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq_broker | >= 6.0.0 < 6.2.7 | 6.2.7 |
| candlepinproject | candlepin | — | — |
| log4j_2 | log4j | — | — |
| satellite_el8 | candlepin | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.activemq/activemq-broker: org.apache.activemq/activemq-core: org.apache.activemq/activemq-all: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entri
vendor_redhat·2026-06-30·CVSS 7.5
CVE-2026-49434 [HIGH] CWE-90 org.apache.activemq/activemq-broker: org.apache.activemq/activemq-core: org.apache.activemq/activemq-all: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entri
org.apache.activemq/activemq-broker: org.apache.activemq/activemq-core: org.apache.activemq/activemq-all: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries
A flaw was found in Apache ActiveMQ. An attacker with privileges to publish or modify entries in Lightweight Directory Access Protocol (LDAP) can exploit an improper input validation vulnerability. This allows the attacker to instantiate denied transports within the broker's Java Virtual Machine (JVM). Consequently, this can be used to fetch an attacker-controlled URL and launch an additional BrokerService within the same JVM, potentially leading to a denial of service or further system compromise.
Statement: Red Hat products ship Apache ActiveMQ Classic components as transitive dependenc
VulDB
Apache ActiveMQ up to 5.19.7/6.2.6 LdapNetworkConnector input validation (EUVD-2026-40285)
vuldb·2026-07-03·CVSS 7.5
CVE-2026-49434 [HIGH] Apache ActiveMQ up to 5.19.7/6.2.6 LdapNetworkConnector input validation (EUVD-2026-40285)
A vulnerability was found in Apache ActiveMQ up to 5.19.7/6.2.6. It has been rated as critical. This vulnerability affects unknown code of the component LdapNetworkConnector. This manipulation causes improper input validation.
This vulnerability appears as CVE-2026-49434. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
GHSA
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
ghsa_unreviewed·2026-06-30
CVE-2026-49434 [HIGH] CWE-20 Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM.
This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-49434 org.apache.activemq/activemq-broker: org.apache.activemq/activemq-core: org.apache.activemq/activemq-all: Apache ActiveMQ: Unauthorized broker instantiation via improper input validatio
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-49434 [HIGH] CVE-2026-49434 org.apache.activemq/activemq-broker: org.apache.activemq/activemq-core: org.apache.activemq/activemq-all: Apache ActiveMQ: Unauthorized broker instantiation via improper input validatio
CVE-2026-49434 org.apache.activemq/activemq-broker: org.apache.activemq/activemq-core: org.apache.activemq/activemq-all: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM.
This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Bugzilla
CVE-2026-49434 log4j: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-49434 [HIGH] CVE-2026-49434 log4j: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [fedora-all]
CVE-2026-49434 log4j: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM.
This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6
Bugzilla
CVE-2026-49434 activemq-cpp: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-49434 [HIGH] CVE-2026-49434 activemq-cpp: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [fedora-all]
CVE-2026-49434 activemq-cpp: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM.
This issue affects Apache ActiveMQ Broker: before 5.19.8,
Bugzilla
CVE-2026-49434 activemq-cpp: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [epel-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-49434 [HIGH] CVE-2026-49434 activemq-cpp: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [epel-all]
CVE-2026-49434 activemq-cpp: Apache ActiveMQ: Unauthorized broker instantiation via improper input validation in LDAP entries [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM.
This issue affects Apache ActiveMQ Broker: before 5.19.8, f
2026-06-30
Published