CVE-2026-34197
Apache ActiveMQ Improper Input Validation Vulnerability
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
2 articles across 2 outlets · first covered Apr 8, 2026 · latest Apr 8, 2026
Coverage timeline
-
RCE Bug Lurked in Apache ActiveMQ Classic for 13 Yearswww.securityweek.com · Apr 8, 2026
-
AI powered tool finds decade old Apache ActiveMQ Classic RCE flawwww.infosecurity-magazine.com · Apr 8, 2026