CVE-2026-49434Disclousre(apache / activemq)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerService inside the same JVM. This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq
  • activemq_broker

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclousre: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
activemqactivemq_broker

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-30: 2Technical Details · 2026-06-30: 206-30
Signal classification2 categories
Disclousre
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-49434 Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in … https://www.cve.org/CVERecord?id=CVE-2026-49434

    Post summary

    The passage provides a brief description of CVE‑2026‑49434 as an improper input validation flaw in Apache ActiveMQ, noting potential attacker actions, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00010684
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclousre

    🚨*CVE* CVE-2026-49434 Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in … https://www.cve.org/CVERecord?id=CVE-2026-49434 ----- Traducción: CVE-2026-49434 Vul… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑49434 as an improper input validation vulnerability in Apache ActiveMQ and provides a link to the official CVE record.

    0000027
    89 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---
Appapacheactivemq_broker---

Explore more