CVE-2026-34197 is a code injection vulnerability in Apache ActiveMQ that exploits improper input validation in the Jolokia JMX-HTTP bridge exposed at /api/jolokia/. An authenticated attacker can invoke the BrokerService.addNetworkConnector or addConnector operations with a malicious Spring XML configuration URI, which triggers arbitrary code execution through Spring bean instantiation before configuration validation occurs. The vulnerability affects Apache ActiveMQ versions before 5.19.4 and versions 6.0.0 through 6.2.2. The vulnerability carries a CVSS 3.1 score of 8.8 (High) with a network attack vector, low complexity, and only low privilege requirements. An authenticated attacker can achieve complete system compromise, including confidentiality, integrity, and availability impacts on the broker's JVM. The EPSS score of 0.625 indicates this vulnerability ranks higher in exploitability than 98.4% of all CVEs. This vulnerability is actively exploited in the wild and appears on the CISA Known Exploited Vulnerabilities catalog with confirmed public exploit code available. The high FAUCET risk score of 96.0 and inclusion on the Hot List indicate significant community attention and real-world threat activity. Apache has released patched versions 5.19.4 and 6.2.3, and immediate patching is strongly recommended for all affected deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.19.4CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.2.3CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
< 5.19.4CPE matchmatch criteria | cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.2.3CPE matchmatch criteria | cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2026-40466: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
Apr 23, 2026Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeans
Apr 7, 2026CVE-2026-34197: Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Apr 6, 2026