Skip to main content
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryprivilege-escalation-methodidentity-authentication-vulnerability

Apache ActiveMQ Jolokia Flaws Enable Broker Control and Remote Code Execution

Updated 2d agoFirst seen Jun 1, 20264 sources

Apache ActiveMQ disclosed two related Jolokia security flaws that let authenticated low-privilege web users perform actions intended for administrators and, in more severe cases, execute arbitrary code on the broker JVM. The first issue, tracked as CVE-2026-49157, stems from incorrect default Jolokia authorization settings in the web console, allowing non-admin accounts to retain broker-management access and carry out operations such as adding or removing queues.

A second flaw, CVE-2026-42588, allows remote code execution through the Jolokia JMX-HTTP bridge exposed at /api/jolokia/ by invoking MBean exec operations such as BrokerService.addNetworkConnector(String). A crafted masterslave:// discovery URI can abuse the VM transport's brokerConfig parameter to load a Spring XML application context via ResourceXmlApplicationContext, enabling code execution before configuration validation completes. Both vulnerabilities affect Apache ActiveMQ versions before 5.19.7 and versions from 6.0.0 before 6.2.6, and Apache has advised users to upgrade to those fixed releases.

Share:
Apache ActiveMQ Jolokia Flaws Enable Broker Control and Remote Code Execution
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 3, 20262d ago

CVE-2026-42253 disclosed in ActiveMQ MessageServlet header injection

A newly reported critical flaw, CVE-2026-42253, allows HTTP response header injection via improperly sanitized JMS message properties in ActiveMQ's MessageServlet used by the web console API. The issue affects versions before 5.19.7 and 6.0.0 through 6.2.5, and Apache addressed it by disabling and deprecating MessageServlet in patched releases.

Critical Apache ActiveMQ Vulnerability Allows Malicious Security Header Injections
Jun 2, 20263d ago

CVE-2026-45505 disclosed as another critical ActiveMQ Jolokia flaw

Reporting identified CVE-2026-45505 as a newly disclosed critical Apache ActiveMQ vulnerability affecting the Jolokia/web console management path. Under certain conditions, it can allow attackers to load malicious configurations and achieve arbitrary code execution.

ActiveMQ Security Flaws Expose Message Brokers
Jun 1, 20265d ago

CVE-2026-42588 details ActiveMQ RCE via Jolokia addNetworkConnector

Technical details were published for CVE-2026-42588, describing how an authenticated attacker could use Jolokia's exec operations on ActiveMQ MBeans and a crafted masterslave:// URI to trigger Spring XML loading and achieve arbitrary code execution on the broker JVM. The issue affects Apache ActiveMQ versions before 5.19.7 and 6.0.0 through before 6.2.6.

CVE-2026-42588 - Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
May 31, 20266d ago

Apache recommends fixed ActiveMQ versions 5.19.7 and 6.2.6

In its vulnerability disclosure, Apache recommended upgrading ActiveMQ to versions 5.19.7 or 6.2.6 to remediate the Jolokia-related security issue. The same affected-version ranges are also cited in reporting on CVE-2026-42588.

CVE-2026-49157: Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default-Apache Mail Archives

Apache discloses CVE-2026-49157 in ActiveMQ Jolokia permissions

Apache ActiveMQ disclosed CVE-2026-49157, an incorrect default-permissions flaw in Jolokia authorization that let authenticated low-privilege web users retain broker-management capabilities intended for administrators. The issue affects versions before 5.19.7 and 6.0.0 through before 6.2.6, and Apache said it was reported by Leon Johnson.

CVE-2026-49157: Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default-Apache Mail Archives
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.