Home

Description

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

PUBLISHED Reserved 2026-05-27 | Published 2026-06-01 | Updated 2026-06-01 | Assigner apache

Problem types

CWE-276 Incorrect Default Permissions

Product status

Default status
unaffected

Any version before 5.19.7
affected

6.0.0 (semver) before 6.2.6
affected

Credits

Leon Johnson (github: lokerxx) finder

References

www.openwall.com/lists/oss-security/2026/05/31/21

lists.apache.org/thread/rrcsf6s90hj4tdh89nvkko75q5505rj8 vendor-advisory

cve.org (CVE-2026-49157)

nvd.nist.gov (CVE-2026-49157)

Download JSON