Description
Improper Authorization vulnerability in Apache ActiveMQ.

An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins.
This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.

Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Published: 2026-06-30
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated low‑privilege user of the ActiveMQ Web Console can access administrative paths (/admin/*) that are intended for administrators only. The flaw is caused by Jetty’s default configuration, which does not enforce the proper authorization policy, permitting unauthorized privilege escalation. The vulnerability is classified as CWE‑285, reflecting an improper use of privileges. The consequence is that an attacker who can log in through the web console, even with limited rights, gains the ability to perform potentially dangerous management operations on the broker, thereby compromising system integrity and possibly availability.

Affected Systems

This issue affects Apache ActiveMQ versions before 5.19.8 and before 6.2.7. The affected products are Apache ActiveMQ Web Console deployments that rely on the default Jetty configuration and have not applied the cited version updates.

Risk and Exploitability

The likely attack vector is authenticating through the web console with a low‑privilege account and then accessing the /admin/* paths, which the default configuration permits. The CVSS score of 8.1 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been documented. Nonetheless, because the exploit requires only an authenticated account and provides unrestricted broker control, the risk remains significant for environments where the console is accessible from untrusted networks.

Generated by OpenCVE AI on June 30, 2026 at 15:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ActiveMQ to version 6.2.7 or 5.19.8, which removes the accidental permission for low‑privilege users to access /admin/* paths.
  • If upgrading immediately is not possible, modify the Jetty configuration to restrict the /admin/* servlet paths so that only users with the admin role can access them.
  • Where the web console is accessible from the external network, restrict access using firewalls or VPNs to limit exposure to trusted administrators.

Generated by OpenCVE AI on June 30, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq
Vendors & Products Apache
Apache activemq

Tue, 30 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
Description Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Title Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console
Weaknesses CWE-285
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-06-30T12:29:12.251Z

Reserved: 2026-06-02T13:37:55.228Z

Link: CVE-2026-49877

cve-icon Vulnrichment

Updated: 2026-06-30T11:06:09.219Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T16:00:15Z

Weaknesses