CVE-2026-52760 Details
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that has been crafted to contain HTML/JavaScript such that when an administrator browses the queue in the Web Console, the payload executes in their browser. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Web Console: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
A cross-site scripting (XSS) vulnerability has been identified in Apache ActiveMQ and the Apache ActiveMQ Web Console. This issue arises because the web console's browse page directly renders JMS message IDs without proper sanitization. As a result, an authenticated producer can send a message containing a crafted ID that includes HTML or JavaScript. When an administrator views the queue in the web console, the embedded payload is executed in their browser. This vulnerability affects Apache ActiveMQ versions prior to 5.19.8 and from 6.0.0 prior to 6.2.7, as well as the Apache ActiveMQ Web Console in the same version ranges.
Users are advised to upgrade to Apache ActiveMQ version 6.2.7 or 5.19.8, both of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/29/12 | CVE | Third Party Advisory |
| https://lists.apache.org/thread/d3mhyo2116nomz2lwxppyy4pclvdxq3n | [email protected] | Vendor AdvisoryMailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | < 5.19.8 >= 6.0.0, < 6.2.7 |
CPE
Remediation
| |
| apache activemq web | < 5.19.8 >= 6.0.0, < 6.2.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | CVE Modified | CVE |
| Jun 30, 2026 | New CVE Received | [email protected] |