← Zurück zur CVE-Suche

CVE-2026-42588

Apache ActiveMQ

Beschreibung

Improper Input Validation, Improper Control of Generation of Code (-Code Injection-) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport-s brokerConfig parameter using the -masterslave:// - URL which can allow loading a Spring XML application context using ResourceXmlApplicationContext. Because Spring-s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker-s JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.

CVSS 8.1EPSS 0.5660000000000001%Risiko 0.85
Quelle öffnen
Veröffentlicht
2026-06-01 09:16:19
Betroffene Versionen
<5.19.7
Typ
Core software
Zuletzt geändert
2026-07-22 07:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N