Vulnerabilità ed exploit

ActiveMQ Management Endpoints Enable Credentialed RCE

Exposed Jolokia management endpoints turn long-lived ActiveMQ Classic deployments into remote code execution targets. The standard response of patching the broker misses the bigger problem: if attackers already have credentials, or if Jolokia is exposed without auth on affected 6.0.0–6.1.1 builds, they can reach arbitrary OS command execution through the management plane.

CISA added CVE-2026-34197 to KEV and set an April 30, 2026 deadline for FCEB agencies. The flaw is an improper input-validation issue in Apache ActiveMQ Classic that affects org.apache.activemq:activemq-broker and org.apache.activemq:activemq-all before 5.19.4, and 6.0.0 before 6.2.3; Apache says 5.19.4 and 6.2.3 fix it.

The risk persists in environments that left default credentials in place or exposed Jolokia for convenience. In those deployments, exploitation does not require new technique development, so legacy brokers remain a ready-made path to code execution.

4 fonti · 22 apr

Valutazione della community

Government advisory confirms CVE-2026-34197 in the KEV Catalog, while security media and threat researchers report active exploitation via the Jolokia API and note chaining with CVE-2024-32114 can produce unauthenticated RCE on some versions.

CVE-2026-34197

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 15% (97º percentile).

Data di correzione federale CISA 30 apr

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-17

Every edition of this story: ActiveMQ Management Endpoints Enable Credentialed RCE

Altro da oggi