AI description
CVE-2026-42588 describes a vulnerability found in Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ. This flaw stems from improper input validation and a code injection vulnerability within the Jolokia JMX-HTTP bridge, which is exposed on the web console at `/api/jolokia/`. An authenticated attacker can exploit this by crafting a discovery URI. This URI triggers the VM transport's `brokerConfig` parameter using a "masterslave://" URL, which allows for loading a Spring XML application context via `ResourceXmlApplicationContext`. Because Spring's `ResourceXmlApplicationContext` instantiates all singleton beans before the `BrokerService` validates the configuration, this can lead to arbitrary code execution on the broker's Java Virtual Machine (JVM) through bean factory methods like `Runtime.exec()`. Affected versions include Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ before 5.19.7, and from 6.0.0 before 6.2.6. Users are advised to upgrade to version 5.19.7 or 6.2.6 to address this issue.
- Description
- Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter using the "masterslave:// " URL which can allow loading a Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- activemq, activemq_broker
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
- security@apache.org
- CWE-20
- Hype score
- Not currently trending
Apache ActiveMQ、危険度の高い脆弱性など4件を修正-CVE-2026-42588-CVE-2026-45505 https://t.co/zOc1Z6HNTw #セキュリティ対策Lab #security #securitynews
@securityLab_jp
4 Jun 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: #Apache patched 3 vulnerabilities in Apache #ActiveMQ. CVE-2026-45505; CVSS:8.0, CVE-2026-49157; CVSS:8.8 & CVE-2026-42588; CVSS:8.1 may lead to high confidentiality, integrity and availability impact in affected versions. Time to #Patch #Patch #Patch
@CCBalert
2 Jun 2026
152 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#CVE-2026-42253 Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties #CVE-2026-42588 Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector These two vulnerabilities we reported have been credited. https://t.co/S385zgrs2v
@pyn3rd
1 Jun 2026
1007 Impressions
0 Retweets
12 Likes
2 Bookmarks
1 Reply
0 Quotes
CVE-2026-42588 CVE-2026-42588 https://t.co/0GIZ5NT80w
@VulmonFeeds
31 May 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*",
"matchCriteriaId": "793E68E6-9024-4518-B062-42B2DE5BB555",
"versionEndExcluding": "5.19.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FFF44DB9-1850-4B5F-AD0F-55CB5219AB22",
"versionEndExcluding": "6.2.6",
"versionStartIncluding": "6.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FE27E832-0E65-4D05-A2EE-271152799E96",
"versionEndExcluding": "5.19.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*",
"matchCriteriaId": "94F0DB6E-BEF4-4BEB-92F5-3A7B65172CC2",
"versionEndExcluding": "6.2.6",
"versionStartIncluding": "6.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]