CVE-2026-54475: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to consume from another connection's temporary destination. This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQ Broker / Apache ActiveMQ All / Apache ActiveMQto a version that resolves this vulnerability.Fixed in 6.2.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54475?
CVE-2026-54475 has a risk rating of 30 indicating a significant security vulnerability.
How do I fix CVE-2026-54475?
To fix CVE-2026-54475, update to the latest version of Apache ActiveMQ that addresses the temporary destination ownership issue.
What are the affected software versions for CVE-2026-54475?
CVE-2026-54475 affects Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ Classic versions that do not enforce proper isolation for temporary destinations.
What type of vulnerability is CVE-2026-54475?
CVE-2026-54475 is classified as a missing authorization vulnerability that can lead to unauthorized access to temporary destinations.
What impact does CVE-2026-54475 have on Apache ActiveMQ security?
CVE-2026-54475 can allow attackers to take over temporary destination ownership, compromising the security and data integrity of the messaging system.