Vulnerability intelligence
CVE-2026-49157
Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
CVSS Score
8.8
High
EPSS — Exploit Probability
0.4%
Riskier than 34% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jun 2, 2026 · latest Jun 2, 2026
Coverage timeline
-
ActiveMQ bugs let attackers run code and bypass defencessecurityonline.info · Jun 2, 2026