← Back to CVE List
Vulnerability Intelligence Report
Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default

CVE-2026-49157

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:0.42%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-276 ↗CWE-276 Incorrect Default Permissions

Affected Products & Versions

Vendor Product Affected Versions
Apache Software Foundation Apache ActiveMQ 0 < 5.19.7 (affected), 6.0.0 < 6.2.6 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.424%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2026-05-27T21:28:11
Published2026-06-01T07:20:10
Last Updated2026-06-01T14:42:33

LINK COPIED TO CLIPBOARD