VYPR
High severity8.1NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026

CVE-2026-49877

CVE-2026-49877

Description

Improper Authorization vulnerability in Apache ActiveMQ.

An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.

Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

Affected products

4
  • Apache/Activemqinferred3 versions
    >=6.0.0,<6.2.7+ 2 more
    • (no CPE)range: >=6.0.0,<6.2.7
    • cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*range: <5.19.8
    • (no CPE)range: <5.19.8, >=6.0.0 <6.2.7
  • osv-coords
    Range: < 5.19.8

Patches

Vulnerability mechanics

References

2

News mentions

4