Severity: moderate Affected versions: - Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) 6.0.0 before 6.3.2 - Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) before 5.19.11 - Apache ActiveMQ All (org.apache.activemq:activemq-all) 6.0.0 before 6.3.2 - Apache ActiveMQ All (org.apache.activemq:activemq-all) before 5.19.11 - Apache ActiveMQ (org.apache.activemq:apache-activemq) 6.0.0 before 6.3.2 - Apache ActiveMQ (org.apache.activemq:apache-activemq) before 5.19.11 Description: Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue. Credit: Wanxin Yin (finder) References: https://activemq.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-74761