https://seclists.org/oss-sec/2026/q2/209: CVE-2026-41044: Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
Published Apr 23, 2026
·Updated
Affected Software
3 affected components
maven/org.apache.activemq/apache-activemq<5.19.6, >=6.0.0<6.2.5
maven/org.apache.activemq/activemq-broker<5.19.6, >=6.0.0<6.2.5
maven/org.apache.activemq/activemq-all<5.19.6, >=6.0.0<6.2.5
Frequently Asked Questions
1
What is the severity of CVE-2026-41044?
CVE-2026-41044 has a severity rating of important.
2
Which versions are affected by CVE-2026-41044?
CVE-2026-41044 affects Apache ActiveMQ versions before 5.19.6, 6.0.0 before 6.2.5, and Apache ActiveMQ Broker before 5.19.6.
3
How can I fix CVE-2026-41044?
To fix CVE-2026-41044, upgrade to Apache ActiveMQ version 5.19.6 or higher, or 6.2.5 or higher.
4
What type of vulnerability is CVE-2026-41044?
CVE-2026-41044 is a remote code execution (RCE) vulnerability that can be exploited by authenticated users via the DestinationView MBean exposed by Jolokia.
5
What components are involved in CVE-2026-41044?
CVE-2026-41044 involves components such as Apache ActiveMQ, Apache ActiveMQ Broker, and Jolokia.