https://seclists.org/oss-sec/2026/q2/757: CVE-2026-45505: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass
Published May 31, 2026
·Updated
Affected Software
3 affected components
maven/org.apache.activemq/activemq-broker<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/activemq-all<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/apache-activemq<5.19.7, >=6.0.0<6.2.6
Frequently Asked Questions
1
What is the severity of CVE-2026-45505?
CVE-2026-45505 has been classified as having important severity.
2
What versions of Apache ActiveMQ are affected by CVE-2026-45505?
CVE-2026-45505 affects Apache ActiveMQ Broker versions before 5.19.7 and 6.0.0 before 6.2.6, as well as Apache ActiveMQ All versions before 5.19.7.
3
How do I fix CVE-2026-45505?
To fix CVE-2026-45505, upgrade to Apache ActiveMQ Broker version 5.19.7 or 6.2.6 and Apache ActiveMQ All version 5.19.7 or later.
4
What is the nature of the vulnerability in CVE-2026-45505?
CVE-2026-45505 allows for a bypass of the Jolokia `addNetworkConnector` discovery wrapper.
5
Are there any workarounds for CVE-2026-45505?
There are no official workarounds for CVE-2026-45505; upgrading to a fixed version is recommended.