CVE-2026-52760: Apache ActiveMQ
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that has been crafted to contain HTML/JavaScript such that when an administrator browses the queue in the Web Console, the payload executes in their browser. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Web Console: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected products
- Apache ActiveMQ: before 5.19.8 (fixed in 5.19.8); from 6.0.0, before 6.2.7 (fixed in 6.2.7)
- Apache ActiveMQ Web: before 5.19.8 (fixed in 5.19.8); from 6.0.0, before 6.2.7 (fixed in 6.2.7)
Published 2026-06-30. Last modified 2026-07-02.