Junglewise Threat Intelligence

CVE-2026-49877: Apache ActiveMQ improper authorization in Web Console

CVE-2026-49877 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Apache ActiveMQ. Vendors: Apache.

Executive brief

Apache ActiveMQ is a popular open-source message broker used to facilitate communication between different software applications. A security flaw in its Web Console allows users with low-level access to view and interact with administrative pages that should be restricted to administrators. This could allow unauthorized users to view sensitive system information or perform administrative actions, potentially disrupting message delivery or exposing internal configurations.

Technical details

An improper authorization vulnerability exists in the Apache ActiveMQ Web Console due to incorrect default Jetty configurations. Specifically, the software fails to restrict access to the '/admin/*' URI paths to users with administrative roles. As a result, any authenticated user, regardless of their privilege level, can access these administrative endpoints. An attacker with valid low-privilege credentials can exploit this over the network to perform unauthorized administrative tasks or access sensitive management data. The issue is resolved in versions 5.19.8 and 6.2.7.

Affected products

  • Apache ActiveMQ before 5.19.8, 6.0.0 to 6.2.6

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References

Related threats