Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-49877

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Improper Authorization vulnerability in Apache ActiveMQ.

An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.

Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
Версия до 5.19.8 (исключая)
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
Версия от 6.0.0 (включая) до 6.2.7 (исключая)

EPSS

Процентиль: 52%
0.0078
Низкий

8.1 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 1 месяца назад

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

CVSS3: 8.1
debian
около 1 месяца назад

Improper Authorization vulnerability in Apache ActiveMQ. An authentic ...

CVSS3: 8.1
github
около 1 месяца назад

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

EPSS

Процентиль: 52%
0.0078
Низкий

8.1 High

CVSS3

Дефекты

CWE-285