CVE-2026-49877 Details
Description
Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
A vulnerability allowing improper authorization has been identified in Apache ActiveMQ versions prior to 5.19.8 and from 6.0.0 prior to 6.2.7. This issue allows authenticated low-privilege users to access '/admin/*' paths in the Web Console by default. The problem arises from incorrect default Jetty settings that did not restrict these paths to admin users only.
Users are advised to upgrade to Apache ActiveMQ version 6.2.7 or 5.19.8, both of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/29/9 | CVE | Third Party Advisory |
| https://lists.apache.org/thread/w82vtc3q02j5ot94tnyy1197y3wb98hl | [email protected] | Vendor AdvisoryMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | < 5.19.8 >= 6.0.0, < 6.2.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | CVE Modified | CVE |
| Jun 30, 2026 | New CVE Received | [email protected] |