Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46605

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

A flaw was found in Apache ActiveMQ server. An authenticated attacker with proper permissions could exploit an incomplete authorization vulnerability to remove existing destinations. This could lead to a Denial of Service (DoS) by disrupting message delivery and processing.

Отчет

Red Hat products ship Apache ActiveMQ Classic components as transitive dependencies. The vulnerability requires running a Classic ActiveMQ broker with multi-user authentication — an authenticated user can remove destinations without proper authorization. Red Hat AMQ Broker is based on Apache ActiveMQ Artemis, a separate codebase. The Classic broker is not deployed as a standalone service in Red Hat products, and the vulnerable authorization code path is not exercised at runtime.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7activemq-artemis-nativeFix deferred
Red Hat AMQ Broker 7activemq-clientFix deferred
Red Hat AMQ Broker 7activemq-openwire-legacyFix deferred
Red Hat AMQ Broker 7apache-artemisFix deferred
Red Hat AMQ Broker 7artemis-amqp-protocolFix deferred
Red Hat AMQ Broker 7artemis-bootFix deferred
Red Hat AMQ Broker 7artemis-cliFix deferred
Red Hat AMQ Broker 7artemis-commonsFix deferred
Red Hat AMQ Broker 7artemis-consoleFix deferred
Red Hat AMQ Broker 7artemis-console-warFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2483784activemq: Apache ActiveMQ: Denial of Service via incomplete authorization

EPSS

Процентиль: 27%
0.00348
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
2 месяца назад

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

CVSS3: 4.3
nvd
2 месяца назад

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.

CVSS3: 4.3
debian
2 месяца назад

Incomplete authorization by Apache ActiveMQ server before versions v6. ...

CVSS3: 4.3
redos
11 дней назад

Уязвимость apache-activemq

CVSS3: 4.3
github
2 месяца назад

Apache ActiveMQ server has an incomplete authorization workflow

EPSS

Процентиль: 27%
0.00348
Низкий

6.5 Medium

CVSS3