Vulnerabilities & Exploits

ActiveMQ Management Endpoints Enable Credentialed RCE

Exposed Jolokia management endpoints turn long-lived ActiveMQ Classic deployments into remote code execution targets. The standard response of patching the broker misses the bigger problem: if attackers already have credentials, or if Jolokia is exposed without auth on affected 6.0.06.1.1 builds, they can reach arbitrary OS command execution through the management plane.

CISA added CVE-2026-34197 to KEV and set an April 30, 2026 deadline for FCEB agencies. The flaw is an improper input-validation issue in Apache ActiveMQ Classic that affects org.apache.activemq:activemq-broker and org.apache.activemq:activemq-all before 5.19.4, and 6.0.0 before 6.2.3; Apache says 5.19.4 and 6.2.3 fix it.

The risk persists in environments that left default credentials in place or exposed Jolokia for convenience. In those deployments, exploitation does not require new technique development, so legacy brokers remain a ready-made path to code execution.

4 sources · Apr 22

Community Assessment

Government advisory confirms CVE-2026-34197 in the KEV Catalog, while security media and threat researchers report active exploitation via the Jolokia API and note chaining with CVE-2024-32114 can produce unauthenticated RCE on some versions.

CVE-2026-34197

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 98% (100th percentile).

CISA federal remediation date Apr 30

Timeline

Sources

Part of the PlainSec briefing for 2026-04-18

Every edition of this story: ActiveMQ Management Endpoints Enable Credentialed RCE

More from today