Incorrect Default Permissions vulnerability in Apache ActiveMQ.
This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.
The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* |
Mon, 01 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache activemq |
|
| Vendors & Products |
Apache
Apache activemq |
Mon, 01 Jun 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue. | |
| Title | Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default | |
| Weaknesses | CWE-276 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2026-06-01T07:20:10.862Z
Updated: 2026-06-01T14:42:33.386Z
Reserved: 2026-05-27T21:28:11.005Z
Link: CVE-2026-49157
Updated: 2026-06-01T07:48:06.780Z
Status : Analyzed
Published: 2026-06-01T09:16:20.427
Modified: 2026-06-01T17:09:59.100
Link: CVE-2026-49157
No data.