CVE-2026-52760

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
30/06/2026
Last modified:
02/07/2026

Description

Improper Neutralization of Input During Web Page Generation (&amp;#39;Cross-site Scripting&amp;#39;) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console.<br /> <br /> The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that has been crafted to contain HTML/JavaScript such that when an administrator browses the queue in the Web Console, the payload executes in their browser.<br /> This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Web Console: before 5.19.8, from 6.0.0 before 6.2.7.<br /> <br /> Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* 5.19.8 (excluding)
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* 6.0.0 (including) 6.2.7 (excluding)
cpe:2.3:a:apache:activemq_web:*:*:*:*:*:*:*:* 5.19.8 (excluding)
cpe:2.3:a:apache:activemq_web:*:*:*:*:*:*:*:* 6.0.0 (including) 6.2.7 (excluding)