https://seclists.org/oss-sec/2026/q2/760: CVE-2026-49270: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosuvia Crafted BrokerInfo (OpenWi)
Published May 31, 2026
·Updated
Affected Software
3 affected components
maven/org.apache.activemq/activemq-broker>=5.14.0<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/activemq-all>=5.14.0<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/apache-activemq>=5.14.0<5.19.7, >=6.0.0<6.2.6
Frequently Asked Questions
1
What is the severity of CVE-2026-49270?
The severity of CVE-2026-49270 is considered moderate.
2
Which versions are affected by CVE-2026-49270?
The affected versions include Apache ActiveMQ Broker 5.14.0 before 5.19.7, 6.0.0 before 6.2.6, and Apache ActiveMQ 5.14.0 before 5.19.7.
3
How do I fix CVE-2026-49270?
To fix CVE-2026-49270, upgrade to Apache ActiveMQ Broker 5.19.7 or higher and Apache ActiveMQ 5.19.7 or higher.
4
What is the vulnerability in CVE-2026-49270?
CVE-2026-49270 is a vulnerability where a crafted BrokerInfo message can lead to disclosure of durable subscription information.
5
Is CVE-2026-49270 patched?
Yes, CVE-2026-49270 has been patched in the fixed releases of the affected software.