Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34197

99
FAUCET Score

CVE-2026-34197 is a code injection vulnerability in Apache ActiveMQ that exploits improper input validation in the Jolokia JMX-HTTP bridge exposed at /api/jolokia/. An authenticated attacker can invoke the BrokerService.addNetworkConnector or addConnector operations with a malicious Spring XML configuration URI, which triggers arbitrary code execution through Spring bean instantiation before configuration validation occurs. The vulnerability affects Apache ActiveMQ versions before 5.19.4 and versions 6.0.0 through 6.2.2. The vulnerability carries a CVSS 3.1 score of 8.8 (High) with a network attack vector, low complexity, and only low privilege requirements. An authenticated attacker can achieve complete system compromise, including confidentiality, integrity, and availability impacts on the broker's JVM. The EPSS score of 0.625 indicates this vulnerability ranks higher in exploitability than 98.4% of all CVEs. This vulnerability is actively exploited in the wild and appears on the CISA Known Exploited Vulnerabilities catalog with confirmed public exploit code available. The high FAUCET risk score of 96.0 and inclusion on the Hot List indicate significant community attention and real-world threat activity. Apache has released patched versions 5.19.4 and 6.2.3, and immediate patching is strongly recommended for all affected deployments.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.19.4CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.2.3CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
< 5.19.4CPE matchmatch criteria
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.2.3CPE matchmatch criteria
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
97.22%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Apr 16, 2026
Metasploit: Apache ActiveMQ RCE via Jolokia addNetworkConnector · Apr 29, 2026
Nuclei: CVE-2026-34197 · Apr 8, 2026
This CVE's current EPSS score of 0.9722 is in the 100th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-brokerFixed in: 5.19.5
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-brokerFixed in: 6.2.3
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-allFixed in: 5.19.5
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-allFixed in: 6.2.3
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (3)

apacheapache:www.mail-archive.com/[email protected]/msg10963.html

CVE-2026-40466: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI

Apr 23, 2026
mavenGHSA-rxpj-7qvf-xv32high

Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeans

Apr 7, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10872.html

CVE-2026-34197: Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans

Apr 6, 2026

References

access.redhat.com / security/cve/CVE-2026-34197
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Third Party Advisory
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-34197.json
Third Party Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
openwall.com / lists/oss-security/2026/04/06/3
Mailing ListThird Party Advisory
activemq.apache.org / security-advisories.data/CVE-2026-34197-announcement.txt
Vendor Advisory