Skip to main content
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryinitial-access-methodproof-of-concept-release

Apache ActiveMQ Jolokia MBean Flaw Enables Authenticated RCE

Updated 1mo agoFirst seen Apr 6, 202622 sources

Apache disclosed CVE-2026-34197, an important-severity remote code execution flaw in Apache ActiveMQ Broker and Apache ActiveMQ Classic that lets authenticated users execute code through the Jolokia JMX-HTTP bridge exposed at /api/jolokia/. The default Jolokia access policy permits exec operations on ActiveMQ MBeans, allowing attackers to call methods such as BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String) with a crafted discovery URI.

The exploit abuses the VM transport brokerConfig parameter to load a remote Spring XML application context via ResourceXmlApplicationContext, and Spring may instantiate singleton beans before ActiveMQ validates the configuration, enabling arbitrary code execution in the broker JVM, including through methods like Runtime.exec(). Apache said the issue affects versions before 5.19.4 in the 5.x line and 6.0.0 through before 6.2.3 in the 6.x line, and recommends upgrading to 5.19.5 or 6.2.3; the vulnerability was reported by Naveen Sunkavally of Horizon3.ai.

Share:
Apache ActiveMQ Jolokia MBean Flaw Enables Authenticated RCE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Apr 23, 20261mo ago

Apache discloses CVE-2026-41044 in ActiveMQ Jolokia DestinationView MBean

Apache disclosed CVE-2026-41044, an important-severity authenticated remote code execution flaw in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All. The issue lets an authenticated attacker craft a malicious broker name through the admin console and abuse the DestinationView MBean exposed by Jolokia to load a remote Spring XML context; Apache said affected versions should be upgraded to 5.19.6 or 6.2.5.

oss-sec: CVE-2026-41044: Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia

Apache discloses CVE-2026-40466 as bypass of ActiveMQ Jolokia RCE fix

Apache disclosed CVE-2026-40466, an important-severity vulnerability that can bypass the CVE-2026-34197 fix in Apache ActiveMQ when the activemq-http module is present. The flaw lets an authenticated attacker use HTTP Discovery transport to reach a malicious endpoint that returns a VM URI and ultimately load a remote Spring XML context for code execution; Apache advised upgrading to versions 5.19.6 or 6.2.5.

oss-sec: CVE-2026-40466: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
Apr 21, 20261mo ago

Shadowserver says 6,400 exposed ActiveMQ servers remain vulnerable

Shadowserver reported that more than 6,400 internet-exposed Apache ActiveMQ servers were still vulnerable to CVE-2026-34197 amid ongoing exploitation. It said the largest concentrations of exposed systems were in Asia, North America, and Europe, highlighting the scale of potential exposure.

Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
Apr 17, 20261mo ago

CISA orders federal agencies to patch ActiveMQ flaw by April 30

After adding CVE-2026-34197 to the KEV catalog, CISA directed Federal Civilian Executive Branch agencies to remediate the Apache ActiveMQ vulnerability under Binding Operational Directive 22-01. The deadline for federal agencies to apply fixes or mitigations was set for 2026-04-30.

CISA tells feds to patch 13-year-old Apache ActiveMQ bug • The Register

CISA adds ActiveMQ CVE-2026-34197 to KEV amid active exploitation

CISA added CVE-2026-34197 to its Known Exploited Vulnerabilities catalog and warned that the Apache ActiveMQ flaw is being actively exploited in the wild. The update elevated the issue from a disclosed and analyzed vulnerability to one with confirmed real-world exploitation.

Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
Apr 7, 20262mo ago

Horizon3.ai publishes exploit details for ActiveMQ Jolokia RCE

Horizon3.ai released technical analysis of CVE-2026-34197, explaining exploitation via Jolokia's addNetworkConnector(String) to load a remote Spring XML file through vm:// and brokerConfig URLs. The post also noted that on ActiveMQ 6.0.0 through 6.1.1, chaining with CVE-2024-32114 can make the flaw effectively unauthenticated, and provided defender monitoring guidance for suspicious vm:// and brokerConfig=xbean:http activity.

CVE-2026-34197 ActiveMQ RCE via Jolokia API | Horizon3.ai
Apr 6, 20262mo ago

Apache publishes remediation guidance for affected ActiveMQ versions

Apache stated the issue affects versions before 5.19.4 in the 5.x line and versions from 6.0.0 before 6.2.3 in the 6.x line. It advised users to upgrade to versions 5.19.5 or 6.2.3 to remediate the vulnerability.

Apache discloses CVE-2026-34197 affecting ActiveMQ Broker and Classic

Apache disclosed an important-severity vulnerability, CVE-2026-34197, in Apache ActiveMQ Broker and Apache ActiveMQ Classic. The flaw allows authenticated users to achieve code execution via Jolokia JMX-HTTP operations such as BrokerService.addNetworkConnector(String) and addConnector(String).

Horizon3.ai researcher reports ActiveMQ Jolokia RCE to Apache

Apache said CVE-2026-34197 was reported by Naveen Sunkavally of Horizon3.ai. The report concerned an authenticated remote code execution path through Jolokia-exposed ActiveMQ MBeans.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.