PatchSiren cyber security CVE debrief
CVE-2026-61487 Apache Software Foundation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T14:16:38.453Z and has not been modified since then. This Improper Authorization vulnerability in Apache ActiveMQ allows an authenticated low-privilege user to bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. The vulnerability affects Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ versions before 5.19.9 and from 6.0.0 before 6.2.8 or 6.3.0. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0, which fixes the issue. Limited evidence is available on the scope of affected systems and users. To verify, defenders should review the official CVE record and NVD details for accuracy and check for any additional information from reliable sources.
- Vendor
- Apache Software Foundation
- Product
- Apache ActiveMQ Broker
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-28
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-07-28
- Advisory updated
- 2026-08-05
Who should care
Users of Apache ActiveMQ, particularly those with low-privilege authenticated users, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and updating ACL configurations for temporary composite destinations and monitoring for unauthorized message publishing. Security teams and vulnerability management teams should prioritize patching and verifying the integrity of their ActiveMQ deployments. Additionally, operators and platform administrators should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.
Technical summary
An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose physical name is a comma-separated composite of real queues. This allows publishing messages to any of the destinations in the list without proper write ACL permissions because the authorization check is bypassed due to the composite destination being marked as temporary. The vulnerability affects Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ versions before 5.19.9 and from 6.0.0 before 6.2.8 or 6.3.0. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0, which fixes the issue. This issue has a CVSS score of 6.5 and a severity of MEDIUM.
Defensive priority
Authenticated low-privilege users can bypass write ACLs by sending messages to temporary composite destinations, allowing unauthorized message publishing.
Recommended defensive actions
- Upgrade to version 5.19.9, 6.2.8, or 6.3.0
- Review and update ACL configurations for temporary composite destinations
- Monitor for unauthorized message publishing
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD details provide information on the Improper Authorization vulnerability in Apache ActiveMQ. Limited evidence is available on the scope of affected systems and users. To verify, defenders should review the official CVE record and NVD details for accuracy and check for any additional information from reliable sources. The vulnerability affects Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ versions before 5.19.9 and from 6.0.0 before 6.2.8 or 6.3.0. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0, which fixes the issue. Evidence of exploitation or affected systems is not publicly available.
Official resources
-
CVE-2026-61487 CVE record
CVE.org
-
CVE-2026-61487 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Mailing List, Vendor Advisory
-
Mitigation or vendor reference
af854a3a-2127-422b-91ae-364da2661108 - Mailing List, Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T14:16:38.453Z and has not been modified since then.