CVE-2026-49157: Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default
Incorrect Default Permissions vulnerability in Apache ActiveMQ.
This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.
The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.
Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 6.2.6 - Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 5.19.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49157?
CVE-2026-49157 has a high severity score of 8.8 according to the CVSS 3.1 standard.
How do I fix CVE-2026-49157?
To fix CVE-2026-49157, upgrade to Apache ActiveMQ version 5.19.7 or later, or 6.2.6 or later.
What does CVE-2026-49157 affect?
CVE-2026-49157 affects Apache ActiveMQ versions before 5.19.7 and versions from 6.0.0 before 6.2.6.
What type of vulnerability is CVE-2026-49157?
CVE-2026-49157 is classified as an Incorrect Default Permissions vulnerability allowing low-privilege users excessive access.
How does CVE-2026-49157 impact security?
CVE-2026-49157 enables authenticated low-privilege web users to perform unauthorized broker management operations.