Cross-site scripting in ActiveMQ - CVE-2026-52760

 

Cross-site scripting in ActiveMQ - CVE-2026-52760

Published: July 1, 2026


Vulnerability identifier: #VU136626
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-52760
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in an administrator's browser.

The vulnerability exists due to cross-site scripting in the browse page of the ActiveMQ Web Console when rendering a JMS message ID without sanitization. A remote user can send a crafted message with a malicious JMS message ID to execute arbitrary script in an administrator's browser.

User interaction is required when an administrator browses the queue in the Web Console.


Affected software

ActiveMQ
openEuler
activemq
activemq-javadoc

How to mitigate CVE-2026-52760

Install security update from vendor's website.

ActiveMQ - addressed in versions 5.19.8, 6.2.7
activemq - update to 5.19.8-1
activemq-javadoc - update to 5.19.8-1

External References

Related Security Bulletins