What is CVE-2026-61487?
CVE-2026-61487 is an improper authorization vulnerability in Apache ActiveMQ Broker. An authenticated low-privilege user can bypass a per-destination write ACL by sending messages to a temporary composite destination with a comma-separated physical name of real queues. Immediate patching is required.
Azərbaycanca: CVE-2026-61487 Apache ActiveMQ broker-da aşkar edilmiş səhv icazə yoxlaması zəifliyidir. Autentifikasiya olunmuş aşağı səviyyəli istifadəçi müvəqqəti kompozit təyinat ünvanı vasitəsilə 'write ACL' məhdudiyyətini keçə bilər. Təcili yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Apache
FAQ2
Which product is affected by CVE-2026-61487?
CVE-2026-61487 affects Apache ActiveMQ Broker.
Does the attacker need to be authenticated to exploit this vulnerability?
Yes, the attacker must be an authenticated low-privilege user to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.