HIGH8.8CVE-2026-49157Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default from 0, < 5.19.7
HIGH8.8CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass from 0, < 5.19.7
HIGH8.8CVE-2024-32114Apache ActiveMQ's default configuration doesn't secure the API web context >= 6.0.0, < 6.1.2
HIGH8.8Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE
from 0, < 5.16.6
HIGH8.1Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
from 0, < 5.19.7
MEDIUM6.5Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues
from 0, < 5.19.6
MEDIUM6.1Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties
from 0, < 5.19.7
MEDIUM5.9Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)
from 0, < 5.19.7
MEDIUM5.4Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated
>= 6.0.0, < 6.2.4
MEDIUM5.4Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated
from 0, < 5.19.2
MEDIUM4.3Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal
from 0, < 5.19.7
—Apache ActiveMQ default configuration subject to denial of service
from 0, < 5.8.0