CVE-2026-42588
Apache ActiveMQ remote code execution through Jolokia addNetworkConnector
Technology
Apache ActiveMQ
CVSS Score
8.1 / 10.0
Affected Versions
before 5.19.7; 6.0.0 before 6.2.6
Upstream Fix
5.19.7 and 6.2.6
Published
June 1, 2026
OSSeva Coverage
Fixed upstream
Description
The default Jolokia access policy on the web console allows exec operations on all ActiveMQ MBeans, including BrokerService.addNetworkConnector. An authenticated attacker can pass a crafted discovery URI that makes the VM transport load a Spring XML application context, and the beans in it are instantiated before the broker validates the configuration, which runs code in the broker JVM. Apache rates the issue important; the 8.1 score on NVD is from CISA-ADP.
Is your Apache ActiveMQ deployment affected?
If you're running before 5.19.7; 6.0.0 before 6.2.6, you need this patch. Book a discovery call to get covered.