CVE-2026-34197: high-severity vulnerability in Apache ActiveMQ
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Authenticated users of Apache ActiveMQ can execute arbitrary code on the server by exploiting a flaw in how the Jolokia web interface validates commands sent to the broker. An attacker sends a specially crafted network connector configuration that tricks the system into loading and running malicious code from a remote location.
CWE-20 (improper input validation) and CWE-94 (code injection) in Apache ActiveMQ's Jolokia JMX-HTTP bridge (/api/jolokia/) allow authenticated attackers to achieve RCE via BrokerService.addNetworkConnector() or addConnector() operations with a malicious discovery URI. The VM transport's brokerConfig parameter loads a remote Spring XML context through ResourceXmlApplicationContext, which instantiates singleton beans before validation, enabling code execution through bean factory methods. Affects versions before 5.19.4 and 6.0.0–6.2.3.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.