https://seclists.org/oss-sec/2026/q3/288: CVE-2026-61487: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Published Jul 27, 2026
·Updated
Affected Software
3 affected components
Apache ActiveMQ Broker
Apache ActiveMQ All
Apache ActiveMQ
Frequently Asked Questions
1
What is the severity of CVE-2026-61487?
CVE-2026-61487 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2026-61487?
To fix CVE-2026-61487, you should upgrade to the latest version of Apache ActiveMQ that includes the required security patches.
3
What does CVE-2026-61487 affect?
CVE-2026-61487 affects the Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ software components.
4
What type of vulnerability is CVE-2026-61487?
CVE-2026-61487 is an authorization bypass vulnerability related to temporary composite destinations.
5
How does CVE-2026-61487 impact security?
CVE-2026-61487 allows unauthorized access to resources, potentially leading to sensitive data exposure.