VYPR
Unrated severityNVD Advisory· Published Sep 9, 2026

CVE-2026-74761

CVE-2026-74761

Description

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms.

An authenticated client can spoof clientId when removing a durable topic subscription.

This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2.

Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.