{"schema_version":"1.7.2","id":"OESA-2026-2723","modified":"2026-06-24T13:12:24Z","published":"2026-06-24T13:12:24Z","upstream":["CVE-2026-42253","CVE-2026-42588","CVE-2026-45505","CVE-2026-46605","CVE-2026-49157","CVE-2026-49270"],"summary":"activemq security update","details":"The most popular and powerful open source messaging and Integration Patterns server.\r\n\r\nSecurity Fix(es):\n\nImproper Neutralization of Input During Web Page Generation (&apos;Cross-site Scripting&apos;) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.\n\nThe MessageServlet in the ActiveMQ web console API copies every JMS message\nproperty into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servlet.\n\nThis issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ Web: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue. The MessageServlet has now been deprecated and disabled by default.(CVE-2026-42253)\n\nImproper Input Validation, Improper Control of Generation of Code (&apos;Code Injection&apos;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\nApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including\nBrokerService.addNetworkConnector(String).\n\nAn authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&apos;s brokerConfig parameter using the &quot;masterslave:// &quot; URL which can allow loading a Spring XML application context using ResourceXmlApplicationContext.\nBecause Spring&apos;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&apos;s JVM through bean factory methods such as Runtime.exec().\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.(CVE-2026-42588)\n\nImproper Input Validation, Improper Control of Generation of Code (&apos;Code Injection&apos;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\n\nNon-parenthesized discovery wrappers such as `masterslave:vm://...,...`\nand `static:vm://...` incorrectly pass validation allowing bypass of fix in CVE-2026-34197. \n\nOriginal description from CVE-2026-34197.\n\nApache ActiveMQ exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery UR that triggers the VM transport&apos;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring&apos;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&apos;s JVM through bean factory methods such as Runtime.exec(). \nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.(CVE-2026-45505)\n\nIncomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.\n\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version v6.2.6 or v5.19.7, which fixes the issue.(CVE-2026-46605)\n\nIncorrect Default Permissions vulnerability in Apache ActiveMQ.\n\nThis issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.\n\nThe default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.\n\nUsers are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.(CVE-2026-49157)\n\nExposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.\n\nBrokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including client identifiers, subscription names, topic destinations, and JMS selector expressions, by sending a BrokerInfo command. The broker incorrectly responds without first ensuring the connection is authenticated.\nThis issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6.\n\nUsers are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.(CVE-2026-49270)","affected":[{"package":{"ecosystem":"openEuler:22.03-LTS-SP4","name":"activemq","purl":"pkg:rpm/openEuler/activemq&distro=openEuler-22.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.19.7-1.oe2203sp4"}]}],"ecosystem_specific":{"noarch":["activemq-5.19.7-1.oe2203sp4.noarch.rpm","activemq-javadoc-5.19.7-1.oe2203sp4.noarch.rpm"],"src":["activemq-5.19.7-1.oe2203sp4.src.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-2723"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42253"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42588"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45505"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46605"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49157"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49270"}],"database_specific":{"severity":"High"}}
