Vulnerability intelligence
CVE-2026-49157
Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
CVSS Score
8.8
High
EPSS — Exploit Probability
0.4%
Riskier than 37% of all CVEs · checked 2026-09-07
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Jun 2, 2026 · latest Jun 2, 2026
Coverage timeline
-
ActiveMQ bugs let attackers run code and bypass defencessecurityonline.info · Jun 2, 2026