Improper Authorization Affecting org.apache.activemq:activemq-broker package, versions [,5.19.9)[6.0.0,6.2.8)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.38% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHEACTIVEMQ-19352104
  • published27 Aug 2026
  • disclosed28 Jul 2026
  • creditClaude and Ada Logics

Introduced: 28 Jul 2026

CVE-2026-61487  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade org.apache.activemq:activemq-broker to version 5.19.9, 6.2.8 or higher.

Overview

org.apache.activemq:activemq-broker is a high performance Apache 2.0 licensed Message Broker and JMS 1.1 implementation.

Affected versions of this package are vulnerable to Improper Authorization in AuthorizationBroker through the temporary-destination write ACL check in AuthorizationBroker.java. An authenticated low-privilege user can publish messages to destinations they are not allowed to write by sending to a temporary composite destination whose physical name is a comma-separated list of real queues. Because the broker treats the composite temporary destination as a temporary destination for ACL evaluation, the per-destination write check is bypassed and messages reach the listed queues without the required write permissions.

CVSS Base Scores

version 4.0
version 3.1