Apache · Activemq Web Console · CVE-2026-52760
**Name of the Vulnerable Software and Affected Versions**
Apache ActiveMQ versions prior to 5.19.8
Apache ActiveMQ versions 6.0.0 through 6.2.6
Apache ActiveMQ Web Console versions prior to 5.19.8
Apache ActiveMQ Web Console versions 6.0.0 through 6.2.6
**Description**
An issue exists where the browse page in the web console renders a message ID without proper sanitization. This allows an authenticated producer to send a message with a crafted JMS message ID containing HTML or JavaScript. When an administrator browses the queue in the Web Console, the malicious payload executes within their browser. This is a Cross-site Scripting (XSS) flaw, which occurs when an application includes untrusted data in a web page without proper validation or encoding.
**Recommendations**
Upgrade to version 5.19.8.
Upgrade to version 6.2.7.