Back to overview

CVE-2026-49877

Description
Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

Metadata

CVE ID
CVE-2026-49877
State
PUBLISHED
Assigner
apache
Reserved
2026-06-02 13:37 UTC
Published
2026-06-30 09:53 UTC
Last updated
2026-06-30 11:06 UTC
Primary CWE
CWE-285
CWE-285 Improper Authorization
Vendor / Product
Apache Software Foundation / Apache ActiveMQ
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Apache Software Foundation Apache ActiveMQ 0 < 5.19.8, 6.0.0 < 6.2.7
Weakness (CWE)
CWESourceDescription
CWE-285 cna CWE-285 Improper Authorization
Back to overview