Junglewise Threat Intelligence

CVE-2026-52760: Apache ActiveMQ stored XSS in Web Console browse page

CVE-2026-52760 · Severity: info · Published 2026-06-30

Technologies: Apache ActiveMQ. Vendors: Apache.

Executive brief

Apache ActiveMQ is a popular open-source message broker used to facilitate communication between different software applications. A security vulnerability in its management web console allows an attacker to inject malicious scripts into the dashboard. If an administrator views the message queue, these scripts could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the Apache ActiveMQ Web Console. The 'browse' page fails to properly sanitize the JMS message ID before rendering it in the browser. An authenticated producer can craft a malicious message containing HTML or JavaScript within the message ID field. When an administrator views the queue via the Web Console, the payload executes in the context of their session. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in versions 5.19.8 and 6.2.7.

Affected products

  • Apache ActiveMQ before 5.19.8, 6.0.0 before 6.2.7
  • Apache ActiveMQ Web Console before 5.19.8, 6.0.0 before 6.2.7

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References

Related threats