CVE-2026-42588

Published Jun 1, 2026

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-42588 describes a vulnerability found in Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ. This flaw stems from improper input validation and a code injection vulnerability within the Jolokia JMX-HTTP bridge, which is exposed on the web console at `/api/jolokia/`. An authenticated attacker can exploit this by crafting a discovery URI. This URI triggers the VM transport's `brokerConfig` parameter using a "masterslave://" URL, which allows for loading a Spring XML application context via `ResourceXmlApplicationContext`. Because Spring's `ResourceXmlApplicationContext` instantiates all singleton beans before the `BrokerService` validates the configuration, this can lead to arbitrary code execution on the broker's Java Virtual Machine (JVM) through bean factory methods like `Runtime.exec()`. Affected versions include Apache ActiveMQ Broker, Apache ActiveMQ All, and Apache ActiveMQ before 5.19.7, and from 6.0.0 before 6.2.6. Users are advised to upgrade to version 5.19.7 or 6.2.6 to address this issue.

Description
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter using the "masterslave:// " URL which can allow loading a Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ All: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.
Source
security@apache.org
NVD status
Analyzed
Products
activemq, activemq_broker

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity
HIGH

Weaknesses

security@apache.org
CWE-20

Social media

Hype score
Not currently trending
  1. Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings https://t.co/LnYthDBzTo

    @Dinosn

    4 Jul 2026

    3367 Impressions

    6 Retweets

    30 Likes

    14 Bookmarks

    0 Replies

    0 Quotes

  2. GitHub - Catherines77/ActiveMQ-EXPtools: Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588) · GitHub https://t.co/NA37SY4GRO

    @akaclandestine

    8 Jun 2026

    3906 Impressions

    13 Retweets

    49 Likes

    30 Bookmarks

    0 Replies

    0 Quotes

  3. Apache ActiveMQ、危険度の高い脆弱性など4件を修正-CVE-2026-42588-CVE-2026-45505 https://t.co/zOc1Z6HNTw #セキュリティ対策Lab #security #securitynews

    @securityLab_jp

    4 Jun 2026

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Warning: #Apache patched 3 vulnerabilities in Apache #ActiveMQ. CVE-2026-45505; CVSS:8.0, CVE-2026-49157; CVSS:8.8 & CVE-2026-42588; CVSS:8.1 may lead to high confidentiality, integrity and availability impact in affected versions. Time to #Patch #Patch #Patch

    @CCBalert

    2 Jun 2026

    152 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. #CVE-2026-42253 Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties #CVE-2026-42588 Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector These two vulnerabilities we reported have been credited. https://t.co/S385zgrs2v

    @pyn3rd

    1 Jun 2026

    1007 Impressions

    0 Retweets

    12 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2026-42588 CVE-2026-42588 https://t.co/0GIZ5NT80w

    @VulmonFeeds

    31 May 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations