All CVEs
Vulnerability intelligence

CVE-2026-34197

Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ CWE-20

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.

CVSS Score
8.8
High
EPSS — Exploit Probability
98%
Riskier than 100% of all CVEs · checked 2026-09-08
Exploitation
Confirmed in the wild
KEV since 2026-04-16
Remediation
unknown
Federal deadline 2026-04-30
CISA required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-04-30.

NVD entry PoC / advisory CISA KEV

2 articles across 2 outlets · first covered Apr 8, 2026 · latest Apr 8, 2026

Coverage timeline

Related CVEs — Apache