<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:43:30 +0000</lastBuildDate>
    <item>
      <title>BIT-activemq-2026-49157 — Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default</title>
      <link>https://cve.radiocsirt.org/vuln/bit-activemq-2026-49157</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;Incorrect Default Permissions vulnerability in Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.&lt;/p&gt;
&lt;p&gt;The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;Incorrect Default Permissions vulnerability in Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.&lt;/p&gt;
&lt;p&gt;The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-activemq-2026-49157</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</link>
      <description>certfr-2026-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</guid>
    </item>
    <item>
      <title>EUVD-2026-323368</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323368</link>
      <description>EUVD-2026-323368</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323368</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49157</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49157</link>
      <description>&lt;p&gt;Incorrect Default Permissions vulnerability in Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.&lt;/p&gt;
&lt;p&gt;The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incorrect Default Permissions vulnerability in Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.&lt;/p&gt;
&lt;p&gt;The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49157</guid>
    </item>
    <item>
      <title>GHSA-99qx-5qqr-4j95 — Apache ActiveMQ has an Incorrect Default Permissions vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-99qx-5qqr-4j95</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:apache-activemq&lt;/p&gt;
&lt;p&gt;Incorrect Default Permissions vulnerability in Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.&lt;/p&gt;
&lt;p&gt;The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:apache-activemq&lt;/p&gt;
&lt;p&gt;Incorrect Default Permissions vulnerability in Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.&lt;/p&gt;
&lt;p&gt;The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-99qx-5qqr-4j95</guid>
    </item>
    <item>
      <title>OESA-2026-2723 — activemq security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2723</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: activemq&lt;/p&gt;
&lt;p&gt;The most popular and powerful open source messaging and Integration Patterns server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Improper Neutralization of Input During Web Page Generation (&amp;amp;apos;Cross-site Scripting&amp;amp;apos;) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.&lt;/p&gt;
&lt;p&gt;The MessageServlet in the ActiveMQ web console API copies every JMS message
property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servlet.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ Web: before 5.19.7, from 6.0.0 before 6.2.6.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue. The MessageServlet has now been deprecated and disabled by default.(CVE-2026-42253)&lt;/p&gt;
&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;amp;apos;Code Injection&amp;amp;apos;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String).&lt;/p&gt;
&lt;p&gt;An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;amp;apos;s brokerConfig parameter using the &amp;amp;quot;masterslave:// &amp;amp;quot; URL which can allow loading a Spring XML application cont…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: activemq&lt;/p&gt;
&lt;p&gt;The most popular and powerful open source messaging and Integration Patterns server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Improper Neutralization of Input During Web Page Generation (&amp;amp;apos;Cross-site Scripting&amp;amp;apos;) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.&lt;/p&gt;
&lt;p&gt;The MessageServlet in the ActiveMQ web console API copies every JMS message
property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servlet.&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ Web: before 5.19.7, from 6.0.0 before 6.2.6.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue. The MessageServlet has now been deprecated and disabled by default.(CVE-2026-42253)&lt;/p&gt;
&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;amp;apos;Code Injection&amp;amp;apos;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String).&lt;/p&gt;
&lt;p&gt;An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;amp;apos;s brokerConfig parameter using the &amp;amp;quot;masterslave:// &amp;amp;quot; URL which can allow loading a Spring XML application cont…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2723</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-49157</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49157</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq, Ubuntu:24.04:LTS: activemq, Ubuntu:25.10: activemq, Ubuntu:26.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq, Ubuntu:24.04:LTS: activemq, Ubuntu:25.10: activemq, Ubuntu:26.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. Users are recommended to upgrade to version 6.2.6 or 5.19.7, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49157</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1741 — Apache ActiveMQ: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1741</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache ActiveMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Informationen offenzulegen, seine Rechte zu erweitern, Daten zu manipulieren und Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache ActiveMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Informationen offenzulegen, seine Rechte zu erweitern, Daten zu manipulieren und Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1741</guid>
    </item>
  </channel>
</rss>
