High severity8.1NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-49877
CVE-2026-49877
Description
Improper Authorization vulnerability in Apache ActiveMQ.
An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected products
4Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/29/9nvdThird Party Advisory
- lists.apache.org/thread/w82vtc3q02j5ot94tnyy1197y3wb98hlnvdVendor AdvisoryMailing List
News mentions
4- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- Multiple Apache ActiveMQ Vulnerabilities Enable DoS Attacks and Lead to CrashesCyber Security News · Jul 3, 2026
- Apache Software Foundation: 21 Vulnerabilities Across Multiple Products Disclosed in Early July 2026Vypr Intelligence · Jul 3, 2026
- Apache ActiveMQ: Nine Vulnerabilities Disclosed, Affecting Broker and Web ConsoleVypr Intelligence · Jul 2, 2026