CVE-2026-49270: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQ Broker / Apache ActiveMQ / Apache ActiveMQ (All)to a version that resolves this vulnerability.Fixed in 6.2.6 - Upgrade
Upgrade
Apache ActiveMQ Broker / Apache ActiveMQ / Apache ActiveMQ (All)to a version that resolves this vulnerability.Fixed in 5.19.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49270?
CVE-2026-49270 has a medium severity rating of 5.9.
What systems are affected by CVE-2026-49270?
CVE-2026-49270 affects Apache ActiveMQ Broker, Apache ActiveMQ, and Apache ActiveMQ All.
How does CVE-2026-49270 expose sensitive information?
CVE-2026-49270 allows unauthenticated attackers to receive a list of all durable subscriptions due to improperly configured network connectors.
How do I fix CVE-2026-49270?
To mitigate CVE-2026-49270, ensure that the syncDurableSubs option is set to false in your network connector configuration.
What type of vulnerability is CVE-2026-49270?
CVE-2026-49270 is classified as an exposure of sensitive information through metadata vulnerability.