{"id":"CVE-2026-49270","summary":"Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)","details":"Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.\n\nBrokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.","aliases":["BIT-activemq-2026-49270","GHSA-hf52-78x8-6w3w"],"modified":"2026-07-15T01:49:18.111559436Z","published":"2026-06-01T07:19:34.391Z","related":["CGA-2jqg-3j4v-h9vq"],"database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-1230"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49270.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"5.14.0"},{"fixed":"5.19.7"},{"introduced":"6.0.0"},{"fixed":"6.2.6"},{"introduced":"5.14.0"},{"fixed":"5.19.7"},{"introduced":"6.0.0"},{"fixed":"6.2.6"},{"introduced":"5.14.0"},{"fixed":"5.19.7"},{"introduced":"6.0.0"},{"fixed":"6.2.6"}]},{"extracted_events":[{"fixed":"5.19.7"},{"introduced":"6.0.0"},{"fixed":"6.2.6"},{"fixed":"5.19.7"},{"introduced":"6.0.0"},{"fixed":"6.2.6"},{"fixed":"5.19.7"},{"introduced":"6.0.0"},{"fixed":"6.2.6"}],"source":"DESCRIPTION"}]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/05/31/22"},{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49270.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/k3233c1x506z3w7x4z0dqvd86d4v2fr2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49270"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/activemq","events":[{"introduced":"0"},{"fixed":"fa56d21ff2d14b99928917cc0bef2e8830acf15f"},{"introduced":"14bac13f40958c1a1d3d198051eed32facc4abd1"},{"fixed":"bb9523b9847fe235a971256fec7ce6bb5670d14d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.19.7"},{"introduced":"6.0.0"},{"fixed":"6.2.6"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*"}}],"versions":["activemq-6.2.1","activemq-5.19.2","activemq-6.2.0","activemq-5.19.1","activemq-5.19.0","activemq-5.18.6","activemq-5.18.5","activemq-6.1.2","activemq-5.18.4","activemq-6.1.1","activemq-6.1.0","activemq-6.0.0","activemq-5.18.3","activemq-5.18.2","activemq-5.18.1","activemq-5.18.0","activemq-5.16.0","activemq-5.15.0","activemq-5.14.0","activemq-5.13.0","activemq-5.12.0","activemq-5.11.0","activemq-5.10.0","activemq-5.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49270.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}