Improper Authorization in Apache ActiveMQ Web Console
CVE-2026-49877
8.1HIGH
What is CVE-2026-49877?
A vulnerability exists in the Apache ActiveMQ Web Console that allows authenticated low-privilege users to access restricted /admin/* paths due to inadequate default Jetty settings. This oversight permits these users to interact with areas of the console intended exclusively for admin use, posing potential security risks. Users are strongly advised to upgrade to versions 6.2.7 or 5.19.8 to mitigate this vulnerability.
Affected Version(s)
Apache ActiveMQ 0 < 5.19.8
Apache ActiveMQ 6.0.0 < 6.2.7