https://seclists.org/oss-sec/2026/q2/1057: CVE-2026-49434: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a mote-properties broker
Published Jun 29, 2026
·Updated
Affected Software
3 affected components
Apache ActiveMQ Broker<5.19.8, >=6.0.0<6.2.7
Apache ActiveMQ<5.19.8, >=6.0.0<6.2.7
Apache ActiveMQ All<5.19.8, >=6.0.0<6.2.7
Frequently Asked Questions
1
What is the severity of CVE-2026-49434?
CVE-2026-49434 has a moderate severity rating.
2
Which versions are affected by CVE-2026-49434?
CVE-2026-49434 affects Apache ActiveMQ Broker before version 5.19.8, Apache ActiveMQ before version 5.19.8, and Apache ActiveMQ versions 6.0.0 before 6.2.7.
3
How do I fix CVE-2026-49434?
To fix CVE-2026-49434, upgrade Apache ActiveMQ Broker to version 5.19.8 or later, or upgrade Apache ActiveMQ to version 6.2.7 or later.
4
What is the impact of CVE-2026-49434?
CVE-2026-49434 allows the LdapNetworkConnector to instantiate denied transports, potentially compromising security.
5
When was CVE-2026-49434 published?
CVE-2026-49434 was published on June 29, 2026.