Authorization Bypass Through User-Controlled Key Affecting org.apache.activemq:activemq-all package, versions [,5.19.11)[6.0.0,6.3.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.39% (33rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGAPACHEACTIVEMQ-19653597
  • published9 Sept 2026
  • disclosed9 Sept 2026
  • creditWanxin Yin

Introduced: 9 Sep 2026

NewCVE-2026-74761  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade org.apache.activemq:activemq-all to version 5.19.11, 6.3.2 or higher.

Overview

org.apache.activemq:activemq-all is a package that puts together an ActiveMQ jar bundle.

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key through TopicRegion.removeSubscription in activemq-broker/src/main/java/org/apache/activemq/broker/region/TopicRegion.java. An authenticated client can remove another client’s durable topic subscription by sending a RemoveSubscriptionInfo request with a spoofed clientId while using its own connection. This lets the broker match the subscription using the client-supplied clientId instead of the connection identity, so a foreign durable subscription can be deleted and its inactive subscriber state removed from the broker.

CVSS Base Scores

version 4.0
version 3.1