https://seclists.org/oss-sec/2026/q2/208: CVE-2026-41043: Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues
Published Apr 23, 2026
·Updated
Affected Software
2 affected components
maven/org.apache.activemq/apache-activemq<5.19.6, >=6.0.0<6.2.5
maven/org.apache.activemq/activemq-web<5.19.6, >=6.0.0<6.2.5
Frequently Asked Questions
1
What is the severity of CVE-2026-41043?
The severity of CVE-2026-41043 is classified as important.
2
Which versions are affected by CVE-2026-41043?
CVE-2026-41043 affects Apache ActiveMQ before version 5.19.6 and 6.0.0 before 6.2.5, as well as Apache ActiveMQ Web before version 5.19.6.
3
How can I fix CVE-2026-41043?
To fix CVE-2026-41043, upgrade to Apache ActiveMQ version 5.19.6 or 6.2.5 and Apache ActiveMQ Web version 5.19.6 or later.
4
What type of vulnerability is CVE-2026-41043?
CVE-2026-41043 is an XSS (Cross-Site Scripting) vulnerability that occurs when browsing queues in the ActiveMQ Web Console.
5
When was CVE-2026-41043 published?
CVE-2026-41043 was published on April 23, 2026.