Improper access control in ActiveMQ - CVE-2026-49157
Published: June 4, 2026
Vulnerability details
The vulnerability allows a remote user to perform broker management operations.
The vulnerability exists due to improper access control in the Jolokia authorization settings when handling web-login access to Jolokia operations. A remote user can invoke administrative broker management operations such as addQueue and removeQueue to perform broker management operations.
Affected software
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-49157
activemq - update to 5.19.7-1
activemq-javadoc - update to 5.19.7-1