Answer in brief
CVE-2026-34197 records a High severity (CVSS 8.8) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans. The current sources mark it as known exploited. The current feed maps Apache Software Foundation/Apache ActiveMQ (generic), Apache Software Foundation/Apache ActiveMQ All (generic), Apache Software Foundation/Apache ActiveMQ Broker (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-34197 records a High severity (CVSS 8.8) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans. The current sources mark it as known exploited. The current feed maps Apache Software Foundation/Apache ActiveMQ (generic), Apache Software Foundation/Apache ActiveMQ All (generic), Apache Software Foundation/Apache ActiveMQ Broker (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Apache Software Foundation/Apache ActiveMQ (generic), Apache Software Foundation/Apache ActiveMQ All (generic), Apache Software Foundation/Apache ActiveMQ Broker (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Apache Software Foundation/Apache ActiveMQgeneric | >=0 <5.19.4 || >=6.0.0 <6.2.3 | 5.19.4, 6.2.3 |
| Apache Software Foundation/Apache ActiveMQ Allgeneric | >=0 <5.19.4 || >=6.0.0 <6.2.3 | 5.19.4, 6.2.3 |
| Apache Software Foundation/Apache ActiveMQ Brokergeneric | >=0 <5.19.4 || >=6.0.0 <6.2.3 | 5.19.4, 6.2.3 |
Published upstream
Apr 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Apr 16, 2026
Evidence: source:kev:kev:kev:recordImproper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue
Quoted source text, attributed separately from HOL analysis.
CVSS is 8.8. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Apache Software Foundation/Apache ActiveMQ (generic), Apache Software Foundation/Apache ActiveMQ All (generic), Apache Software Foundation/Apache ActiveMQ Broker (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Apache Software Foundation/Apache ActiveMQgeneric | >=0 <5.19.4 || >=6.0.0 <6.2.3 | 5.19.4, 6.2.3 |
| Apache Software Foundation/Apache ActiveMQ Allgeneric | >=0 <5.19.4 || >=6.0.0 <6.2.3 | 5.19.4, 6.2.3 |
| Apache Software Foundation/Apache ActiveMQ Brokergeneric | >=0 <5.19.4 || >=6.0.0 <6.2.3 | 5.19.4, 6.2.3 |
Published upstream
Apr 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Apr 16, 2026
Evidence: source:kev:kev:kev:recordImproper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue
Quoted source text, attributed separately from HOL analysis.