PT-2026-45376 · Apache · Activemq

·

CVE-2026-45505

·

Published

2026-06-01

·

Updated

2026-08-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ Broker versions prior to 5.19.7 Apache ActiveMQ Broker versions 6.0.0 through 6.2.5 Apache ActiveMQ All versions prior to 5.19.7 Apache ActiveMQ All versions 6.0.0 through 6.2.5 Apache ActiveMQ versions prior to 5.19.7 Apache ActiveMQ versions 6.0.0 through 6.2.5
Description Improper input validation and improper control of code generation allow for code injection. The software exposes the Jolokia JMX-HTTP bridge at the '/api/jolokia/' endpoint. The default access policy permits execution operations on ActiveMQ MBeans, specifically the BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String) functions. An authenticated attacker can use a crafted discovery URI, such as masterslave:vm://...,... or static:vm://..., to trigger the brokerConfig parameter of the VM transport. This causes the ResourceXmlApplicationContext to load a remote Spring XML application context. Since singleton beans are instantiated before configuration validation, arbitrary code can be executed on the broker's JVM via bean factory methods like Runtime.exec().
Recommendations Upgrade Apache ActiveMQ Broker versions prior to 5.19.7 to 5.19.7. Upgrade Apache ActiveMQ Broker versions 6.0.0 through 6.2.5 to 6.2.6. Upgrade Apache ActiveMQ All versions prior to 5.19.7 to 5.19.7. Upgrade Apache ActiveMQ All versions 6.0.0 through 6.2.5 to 6.2.6. Upgrade Apache ActiveMQ versions prior to 5.19.7 to 5.19.7. Upgrade Apache ActiveMQ versions 6.0.0 through 6.2.5 to 6.2.6.

Exploit

Fix

DoS

Code Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2026-45505
CVE-2026-45505
GHSA-V853-W46P-FV2H
OESA-2026-2723
OESA-2026-2724
OESA-2026-2725

Affected Products

Activemq