Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-42588

Apache ActiveMQ remote code execution through Jolokia addNetworkConnector

Technology

Apache ActiveMQ

CVSS Score

8.1 / 10.0

Affected Versions

before 5.19.7; 6.0.0 before 6.2.6

Upstream Fix

5.19.7 and 6.2.6

Published

June 1, 2026

OSSeva Coverage

Fixed upstream

Description

The default Jolokia access policy on the web console allows exec operations on all ActiveMQ MBeans, including BrokerService.addNetworkConnector. An authenticated attacker can pass a crafted discovery URI that makes the VM transport load a Spring XML application context, and the beans in it are instantiated before the broker validates the configuration, which runs code in the broker JVM. Apache rates the issue important; the 8.1 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache ActiveMQ deployment affected?

If you're running before 5.19.7; 6.0.0 before 6.2.6, you need this patch. Book a discovery call to get covered.