Home

Description

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

PUBLISHED Reserved 2026-05-28 | Published 2026-06-01 | Updated 2026-06-01 | Assigner apache

Problem types

CWE-1230 Exposure of Sensitive Information Through Metadata

Product status

Default status
unaffected

5.14.0 (semver) before 5.19.7
affected

6.0.0 (semver) before 6.2.6
affected

Default status
unaffected

5.14.0 (semver) before 5.19.7
affected

6.0.0 (semver) before 6.2.6
affected

Default status
unaffected

5.14.0 (semver) before 5.19.7
affected

6.0.0 (semver) before 6.2.6
affected

Credits

Basel Khaled finder

References

www.openwall.com/lists/oss-security/2026/05/31/22

lists.apache.org/thread/k3233c1x506z3w7x4z0dqvd86d4v2fr2 vendor-advisory

cve.org (CVE-2026-49270)

nvd.nist.gov (CVE-2026-49270)

Download JSON