Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45505

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 8.8

Описание

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as masterslave:vm://...,... and static:vm://... incorrectly pass validation allowing bypass of fix in CVE-2026-34197.  Original description from CVE-2026-34197. Apache ActiveMQ exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery UR that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.

A flaw was found in Apache ActiveMQ. This vulnerability allows an authenticated attacker to bypass a previous fix for CVE-2026-34197 by using non-parenthesized discovery wrappers. By crafting a malicious discovery URI, the attacker can trigger the VM transport's brokerConfig parameter to load a remote Spring XML application context, leading to arbitrary code execution on the broker's Java Virtual Machine (JVM).

Отчет

Red Hat products ship Apache ActiveMQ Classic components as transitive dependencies. The vulnerability is an authenticated RCE via Jolokia JMX-over-HTTP on the Classic ActiveMQ web console, bypassing the fix for CVE-2026-34197. The Classic web console with Jolokia is not deployed in any Red Hat product — Red Hat Fuse 7 removed the embedded broker in version 7.0 and ships only client JARs. Red Hat AMQ Broker is based on Apache ActiveMQ Artemis with its own management interface. The Jolokia attack surface does not exist in Red Hat product deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7activemq-artemis-nativeFix deferred
Red Hat AMQ Broker 7activemq-clientFix deferred
Red Hat AMQ Broker 7activemq-openwire-legacyFix deferred
Red Hat AMQ Broker 7apache-artemisFix deferred
Red Hat AMQ Broker 7artemis-amqp-protocolFix deferred
Red Hat AMQ Broker 7artemis-bootFix deferred
Red Hat AMQ Broker 7artemis-cliFix deferred
Red Hat AMQ Broker 7artemis-commonsFix deferred
Red Hat AMQ Broker 7artemis-consoleFix deferred
Red Hat AMQ Broker 7artemis-console-warFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2483779activemq: Apache ActiveMQ: Arbitrary Code Execution via crafted discovery URI bypass

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
2 месяца назад

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` incorrectly pass validation allowing bypass of fix in CVE-2026-34197. Original description from CVE-2026-34197. Apache ActiveMQ exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery UR that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates...

CVSS3: 8.8
nvd
2 месяца назад

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` incorrectly pass validation allowing bypass of fix in CVE-2026-34197.  Original description from CVE-2026-34197. Apache ActiveMQ exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery UR that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService valida

CVSS3: 8.8
debian
2 месяца назад

Improper Input Validation, Improper Control of Generation of Code ('Co ...

CVSS3: 8.8
github
2 месяца назад

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue

8.8 High

CVSS3