Cross-site scripting in ActiveMQ - CVE-2026-41043
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote user to inject malicious content into the web console.
The vulnerability exists due to cross-site scripting in ActiveMQ Web Console when browsing queues. A remote user can inject HTML into a JMS selector field and override the content type to HTML to inject malicious content into the web console.
The issue is triggered while browsing queues in the web console.
Affected software
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-41043
activemq - update to 5.19.6-1
activemq-javadoc - update to 5.19.6-1