Incorrect Default Permissions vulnerability in Apache ActiveMQ.
This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.
The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue. | |
| Title | Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default | |
| Weaknesses | CWE-276 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-01T07:48:06.780Z
Reserved: 2026-05-27T21:28:11.005Z
Link: CVE-2026-49157
No data.
Status : Received
Published: 2026-06-01T09:16:20.427
Modified: 2026-06-01T09:16:20.427
Link: CVE-2026-49157
No data.
OpenCVE Enrichment
No data.