All CVEs
Vulnerability intelligence

CVE-2026-49157

Apache Software Foundation Apache ActiveMQ CWE-276

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

CVSS Score
8.8
High
EPSS — Exploit Probability
0.4%
Riskier than 37% of all CVEs · checked 2026-09-07
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Jun 2, 2026 · latest Jun 2, 2026

Coverage timeline

Related CVEs — Apache Software Foundation