Apache ActiveMQ disclosed two related Jolokia security flaws that let authenticated low-privilege web users perform actions intended for administrators and, in more severe cases, execute arbitrary code on the broker JVM. The first issue, tracked as CVE-2026-49157, stems from incorrect default Jolokia authorization settings in the web console, allowing non-admin accounts to retain broker-management access and carry out operations such as adding or removing queues.
A second flaw, CVE-2026-42588, allows remote code execution through the Jolokia JMX-HTTP bridge exposed at /api/jolokia/ by invoking MBean exec operations such as BrokerService.addNetworkConnector(String). A crafted masterslave:// discovery URI can abuse the VM transport's brokerConfig parameter to load a Spring XML application context via ResourceXmlApplicationContext, enabling code execution before configuration validation completes. Both vulnerabilities affect Apache ActiveMQ versions before 5.19.7 and versions from 6.0.0 before 6.2.6, and Apache has advised users to upgrade to those fixed releases.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A newly reported critical flaw, CVE-2026-42253, allows HTTP response header injection via improperly sanitized JMS message properties in ActiveMQ's MessageServlet used by the web console API. The issue affects versions before 5.19.7 and 6.0.0 through 6.2.5, and Apache addressed it by disabling and deprecating MessageServlet in patched releases.
Reporting identified CVE-2026-45505 as a newly disclosed critical Apache ActiveMQ vulnerability affecting the Jolokia/web console management path. Under certain conditions, it can allow attackers to load malicious configurations and achieve arbitrary code execution.
Technical details were published for CVE-2026-42588, describing how an authenticated attacker could use Jolokia's exec operations on ActiveMQ MBeans and a crafted masterslave:// URI to trigger Spring XML loading and achieve arbitrary code execution on the broker JVM. The issue affects Apache ActiveMQ versions before 5.19.7 and 6.0.0 through before 6.2.6.
In its vulnerability disclosure, Apache recommended upgrading ActiveMQ to versions 5.19.7 or 6.2.6 to remediate the Jolokia-related security issue. The same affected-version ranges are also cited in reporting on CVE-2026-42588.
Apache ActiveMQ disclosed CVE-2026-49157, an incorrect default-permissions flaw in Jolokia authorization that let authenticated low-privilege web users retain broker-management capabilities intended for administrators. The issue affects versions before 5.19.7 and 6.0.0 through before 6.2.6, and Apache said it was reported by Leon Johnson.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcelists.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.