# CVE-2026-74761

## Summary

- **CVE ID:** CVE-2026-74761
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
- **CWE:** CWE-20
- **Published:** Sep 9, 2026
- **Last Modified:** Sep 10, 2026

## Description

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms.




An authenticated client can spoof clientId when removing a durable topic subscription.



This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2.



Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.

## Affected Products

- Apache Software Foundation — Apache ActiveMQ Broker (6.0.0)
- Apache Software Foundation — Apache ActiveMQ Broker (0)
- Apache Software Foundation — Apache ActiveMQ All (6.0.0)
- Apache Software Foundation — Apache ActiveMQ All (0)
- Apache Software Foundation — Apache ActiveMQ (6.0.0)
- Apache Software Foundation — Apache ActiveMQ (0)

## References

- [CNA](https://lists.apache.org/thread/n9md06jo7ccqmj2mntx4kpcl2d5xqntz)
- [CVE](http://www.openwall.com/lists/oss-security/2026/09/08/12)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 9.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._