PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61487 Apache Software Foundation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T14:16:38.453Z and has not been modified since then. This Improper Authorization vulnerability in Apache ActiveMQ allows an authenticated low-privilege user to bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. The vulnerability affects Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ versions before 5.19.9 and from 6.0.0 before 6.2.8 or 6.3.0. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0, which fixes the issue. Limited evidence is available on the scope of affected systems and users. To verify, defenders should review the official CVE record and NVD details for accuracy and check for any additional information from reliable sources.

Vendor
Apache Software Foundation
Product
Apache ActiveMQ Broker
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-28
Original CVE updated
2026-08-05
Advisory published
2026-07-28
Advisory updated
2026-08-05

Who should care

Users of Apache ActiveMQ, particularly those with low-privilege authenticated users, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and updating ACL configurations for temporary composite destinations and monitoring for unauthorized message publishing. Security teams and vulnerability management teams should prioritize patching and verifying the integrity of their ActiveMQ deployments. Additionally, operators and platform administrators should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.

Technical summary

An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. The vulnerability affects Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ versions before 5.19.9 and from 6.0.0 before 6.2.8 or 6.3.0. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0, which fixes the issue. This issue has a CVSS score of 6.5 and a severity of MEDIUM.

Defensive priority

Authenticated low-privilege users can bypass write ACLs by sending messages to temporary composite destinations, allowing unauthorized message publishing.

Recommended defensive actions

  • Upgrade to version 5.19.9, 6.2.8, or 6.3.0
  • Review and update ACL configurations for temporary composite destinations
  • Monitor for unauthorized message publishing
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD details provide information on the Improper Authorization vulnerability in Apache ActiveMQ. Limited evidence is available on the scope of affected systems and users. To verify, defenders should review the official CVE record and NVD details for accuracy and check for any additional information from reliable sources. The vulnerability affects Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ versions before 5.19.9 and from 6.0.0 before 6.2.8 or 6.3.0. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0, which fixes the issue. Evidence of exploitation or affected systems is not publicly available.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T14:16:38.453Z and has not been modified since then.