
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61487 is an Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ that allows authenticated low-privilege users to bypass per-destination write ACLs via temporary composite destinations. It affects Apache ActiveMQ versions before 5.19.9 and from 6.0.0 before 6.2.8 across all three product variants. The vulnerability was disclosed on July 27, 2026, by Christopher L. Shannon via the oss-security mailing list, with credit to Claude and Ada Logics as finders. It carries a CVSS v3.1 base score of 6.5 (Medium) (Apache Advisory, OSS-Sec, GitHub Advisory).
The root cause is CWE-285 (Improper Authorization): the ActiveMQ broker fails to correctly enforce write ACL checks when a destination is classified as temporary. An attacker crafts a temporary composite destination whose physical name is a comma-separated list of real queue names (e.g., temp-queue://realQueue1,realQueue2); because the broker marks the composite destination as temporary, the per-destination authorization check is skipped entirely, allowing messages to be published to any queue in the list. Exploitation requires only valid (low-privilege) credentials and network access to the broker — no special configuration or user interaction is needed (OSS-Sec, GitHub Advisory).
Successful exploitation allows an authenticated low-privilege user to publish messages to any queue on the broker, regardless of configured write ACL restrictions, resulting in a high integrity impact. Confidentiality and availability are not directly affected by this vulnerability. In environments where message queues carry sensitive business logic, commands, or data, unauthorized message injection could lead to data corruption, business process manipulation, or serve as a stepping stone for further attacks within the messaging infrastructure (OSS-Sec, GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the attack is not automatable, as it requires authenticated access. The EPSS score is approximately 0.37–0.49%, placing it in roughly the 39th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
ActiveMQTempQueue with name realQueue1,restrictedQueue2,sensitiveQueue3.ActiveMQTempQueue with composite names).Apache has released patched versions: 5.19.9, 6.2.8, and 6.3.0. Users should upgrade to one of these versions as the primary remediation. As an interim measure, administrators should review and tighten ACL policies, monitor for suspicious composite destination creation patterns, and restrict broker access to only trusted, necessary accounts. No configuration-only workaround has been published by Apache (Apache Advisory, OSS-Sec).
The vulnerability was reported to the oss-security mailing list by Christopher L. Shannon on July 27, 2026, crediting Claude and Ada Logics as finders. Brief social media activity was observed on Bluesky shortly after disclosure. Coverage has been picked up by standard vulnerability aggregators (Vulners, VulDB, CVEFeed) and security scanning vendors including Tenable (Nessus plugins 330631 and 330836) and Qualys (detection ID 531966). No major vendor statements or notable researcher commentary beyond the official advisory have been identified (OSS-Sec, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."