← back
CVE-2026-49270

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)

CVSS 5.9 MEDIUMEPSS 0.3%CWE-1230
In short

Apache ActiveMQ brokers with network connectors can leak sensitive subscription information to unauthenticated attackers. An attacker can obtain details about durable topic subscriptions, client IDs, and filtering rules without logging in.

Technical detail

An unauthenticated attacker can send a crafted BrokerInfo command via OpenWire protocol to brokers configured with syncDurableSubs=true, exploiting missing authentication checks to enumerate all durable subscription metadata including client identifiers, subscription names, destinations, and JMS selector expressions. The vulnerability affects ActiveMQ versions before 5.19.7 and 6.0.0-6.2.5, and requires the broker to have network connectors enabled.

Summary generated and translated by AI from the official description.
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →