Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-49157

Incorrect Default Permissions vulnerability in Apache ActiveMQ.

Technology

Apache ActiveMQ

CVSS Score

8.8 / 10.0

Affected Versions

<5.19.7; >=6.0.0 <6.2.6

Upstream Fix

See upstream advisory

Published

June 1, 2026

OSSeva Coverage

Fixed upstream

Description

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

Is your Apache ActiveMQ deployment affected?

If you're running <5.19.7; >=6.0.0 <6.2.6, you need this patch. Book a discovery call to get covered.