cbcvebase.
CVE-2026-49157
published 2026-06-01

CVE-2026-49157: Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia…

PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.42%
34.4th percentile
Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.

Affected

7 ranges
VendorProductVersion rangeFixed in
apacheactivemq< 5.19.75.19.7
apacheactivemq>= 6.0.0 < 6.2.66.2.6
apache_software_foundationapache_activemq< 5.19.75.19.7
apache_software_foundationapache_activemq>= 6.0.0 < 6.2.66.2.6
candlepinprojectcandlepin
log4j_2log4j
satellite_el8candlepin

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.