Back to CVE List

CVE-2026-46605

Vulnerability Description

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.

This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.

Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-285
Source
NVD
Vendor
Apache Software Foundation
Product
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ

External References

Discussion (0)

Add Comment

No comments yet. Be the first!