CVE-2026-49157

HIGH

Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default

Title source: cna
STIX 2.1

Description

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0037
EPSS Percentile 28.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (3)
apache/activemq < 5.19.7
Apache Software Foundation/Apache ActiveMQ < 5.19.7
Apache Software Foundation/Apache ActiveMQ 6.0.0 - 6.2.6
Published Jun 01, 2026
Tracked Since Jun 01, 2026