HIGHVulnerability

CVE-2026-74761

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-74761
signal_observed_at
2026-09-18T17:46:28+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
published_at
2026-09-09T12:17:13.040
last_modified
2026-09-18T14:37:42.543

Related Entities (5)

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (3)

[Product]
[Product]
[Product]

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-74761 — Ninja Signal Threat Intelligence | Ninja Signal