https://seclists.org/oss-sec/2026/q3/676: CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of moveSubscription clientId
Published Sep 8, 2026
·Updated
Affected Software
3 affected components
Apache ActiveMQ Broker>5.19.11<=, >6.0.0<=6.3.2
Apache ActiveMQ All<5.19.11, >6.0.0<=6.3.2
Apache ActiveMQ<5.19.11, >6.0.0<=6.3.2
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must be an authenticated Apache ActiveMQ client. The issue involves spoofing a clientId while removing a durable topic subscription.
2
Which deployments should be prioritized for remediation?
Prioritize ActiveMQ deployments that allow authenticated clients to use durable topic subscriptions and run affected versions: versions before 5.19.11, or 6.0.0 through before 6.3.2. This applies to the activemq-broker, activemq-all, and apache-activemq artifacts.
3
What versions resolve the issue?
Upgrade to Apache ActiveMQ version 5.19.11 or 6.3.2. These versions fix the improper input validation in TopicRegion.