Improper access control in ActiveMQ - CVE-2026-49157
Published: June 4, 2026
ActiveMQ
Detailed vulnerability description
The vulnerability allows a remote user to perform broker management operations.
The vulnerability exists due to improper access control in the Jolokia authorization settings when handling web-login access to Jolokia operations. A remote user can invoke administrative broker management operations such as addQueue and removeQueue to perform broker management operations.