boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-34197HIGH
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .9722   99.9   YES
AFFECTED
  Product                 Versions     Fixed
  Apache ActiveMQ Broker  unspecified  —
  Apache ActiveMQ All     unspecified  —
  Apache ActiveMQ         unspecified  —
TIMELINE
  Mar 26  Reserved by apache
  Apr 7   Published (CNA: apache)
  Apr 16  Added to CISA KEV, remediation due 2026-04-30
CWE-20, CWE-94 · CNA: apache · CVSS v3.1 · 6 references · NVD status: Analyzed · KEV due April 30, 2026

Description

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 26, 2026ReservedReserved by apache
April 7, 2026PublishedPublished (CNA: apache)
April 16, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-04-30

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Apache Software FoundationApache ActiveMQ BrokerMaven
Apache Software FoundationApache ActiveMQ AllMaven
Apache Software FoundationApache ActiveMQMaven

Weaknesses

CWE-20 · CWE-94

References (6)

Related

Authoritative record: CVE-2026-34197 at cve.org

Vendors: apache

Weaknesses: CWE-20 · CWE-94

Ecosystems: Maven

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-34197 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.