Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-49270

30
FAUCET Score

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

First published: Jun 1, 2026Last modified: Jun 1, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 5.19.7CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.2.6CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
< 5.19.7CPE matchmatch criteria
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.2.6CPE matchmatch criteria
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
29.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 4th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

mavenpatch availablevia ghsa
Product: org.apache.activemq:apache-activemqFixed in: 5.19.7
mavenpatch availablevia ghsa
Product: org.apache.activemq:apache-activemqFixed in: 6.2.6
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-brokerFixed in: 5.19.7
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-brokerFixed in: 6.2.6
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-allFixed in: 5.19.7
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-allFixed in: 6.2.6
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (3)

apacheapache:www.mail-archive.com/[email protected]/msg11322.htmlLOW

CVE-2026-50750: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270

Jun 29, 2026
mavenGHSA-hf52-78x8-6w3wmedium

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability

Jun 1, 2026
apacheapache:www.mail-archive.com/[email protected]/msg11187.html

CVE-2026-49270: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)

May 31, 2026

References

openwall.com / lists/oss-security/2026/05/31/22
Mailing ListThird Party Advisory
lists.apache.org / thread/k3233c1x506z3w7x4z0dqvd86d4v2fr2
Mailing ListVendor Advisory