CVE-2026-49157
HIGHApache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default
Title source: cnaDescription
Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/rrcsf6s90hj4tdh89nvkko75q5505rj8
Scores
CVSS v3
8.8
EPSS
0.0037
EPSS Percentile
28.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (3)
apache/activemq
< 5.19.7
Apache Software Foundation/Apache ActiveMQ
< 5.19.7
Apache Software Foundation/Apache ActiveMQ
6.0.0 - 6.2.6
Published
Jun 01, 2026
Tracked Since
Jun 01, 2026