CVE-2026-46605: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.
This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQ Brokerto a version that resolves this vulnerability.Fixed in 6.2.6 - Upgrade
Upgrade
Apache ActiveMQ Brokerto a version that resolves this vulnerability.Fixed in 5.19.7 - Upgrade
Upgrade
Apache ActiveMQ Allto a version that resolves this vulnerability.Fixed in 6.2.6 - Upgrade
Upgrade
Apache ActiveMQ Allto a version that resolves this vulnerability.Fixed in 5.19.7 - Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 6.2.6 - Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 5.19.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46605?
The severity of CVE-2026-46605 is rated as medium with a CVSS score of 4.3.
How do I fix CVE-2026-46605?
To fix CVE-2026-46605, upgrade Apache ActiveMQ to version 5.19.7 or later, or to version 6.2.6 or later.
What kind of vulnerability is CVE-2026-46605?
CVE-2026-46605 is an incomplete authorization issue that allows authenticated connections to remove existing destinations.
Which versions of ActiveMQ are affected by CVE-2026-46605?
CVE-2026-46605 affects Apache ActiveMQ Broker versions before 5.19.7 and 6.0.0 through 6.2.6.
What are the implications of CVE-2026-46605?
The implications of CVE-2026-46605 include unauthorized access, as authenticated users may delete critical destinations without proper permissions.