Cross-site scripting in ActiveMQ - CVE-2026-41043

 

Cross-site scripting in ActiveMQ - CVE-2026-41043

Published: April 28, 2026


Vulnerability identifier: #VU128311
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-41043
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject malicious content into the web console.

The vulnerability exists due to cross-site scripting in ActiveMQ Web Console when browsing queues. A remote user can inject HTML into a JMS selector field and override the content type to HTML to inject malicious content into the web console.

The issue is triggered while browsing queues in the web console.


Affected software

ActiveMQ
openEuler
activemq
activemq-javadoc

How to mitigate CVE-2026-41043

Install security update from vendor's website.

ActiveMQ - addressed in versions 5.19.6, 6.2.5
activemq - update to 5.19.6-1
activemq-javadoc - update to 5.19.6-1

External References

Related Security Bulletins