← Back to CVE search

CVE-2026-52760

Apache ActiveMQ

Description

Improper Neutralization of Input During Web Page Generation (-Cross-site Scripting-) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that has been crafted to contain HTML/JavaScript such that when an administrator browses the queue in the Web Console, the payload executes in their browser. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Web Console: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

CVSS 6.1EPSS 0.47200000000000003%Risk 0.64
View source
Published
2026-06-30 11:16:30
Affected versions
<5.19.8, >=6.0.0,<6.2.7
Type
Web application
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N