CVE-2026-49877
EUVD-2026-4028330.06.2026, 11:16
Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | activemq | 𝑥 < 5.19.8 | CNA |
| apache | activemq | 6.0.0 ≤ 𝑥 < 6.2.7 | CNA |
Ubuntu Releases
Common Weakness Enumeration
Vulnerability Media Exposure