CVE-2026-49157

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
References
Link Resource
https://lists.apache.org/thread/rrcsf6s90hj4tdh89nvkko75q5505rj8 Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/05/31/21 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*

History

01 Jun 2026, 17:09

Type Values Removed Values Added
References () https://lists.apache.org/thread/rrcsf6s90hj4tdh89nvkko75q5505rj8 - () https://lists.apache.org/thread/rrcsf6s90hj4tdh89nvkko75q5505rj8 - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/05/31/21 - () http://www.openwall.com/lists/oss-security/2026/05/31/21 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
First Time Apache
Apache activemq

01 Jun 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

01 Jun 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 09:16

Updated : 2026-06-01 17:09


NVD link : CVE-2026-49157

Mitre link : CVE-2026-49157

CVE.ORG link : CVE-2026-49157


JSON object : View

Products Affected

apache

  • activemq
CWE
CWE-276

Incorrect Default Permissions