CVE-2026-34197

CVSS 8.8 · HIGH
Exploited in the wild
Remediation overdue by 95 days
EPSS p99
Higher than 99% of all CVEs — imminent exploitation likely.
Patch available
Vendor advisory or patch linked

Published 4/7/2026 · updated 4/16/2026 · CWE-20, CWE-94

Share
Get asset-aware triage

Summary

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue

CVSS 8.8HIGH

8.8 / 10
  • AV: Network
  • AC: Low complexity
  • PR: Low privileges
  • UI: No user interaction
  • S: Scope unchanged
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS exploitation probability

83.5%

Percentile p99 Higher than 99% of all CVEs — imminent exploitation likely.

Affected products

2 vendor/product entries
  • Apache Activemq< 5.19.4
  • Apache Activemq Broker< 5.19.4
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Apr 7, 2026 · Disclosed / published in NVD
  2. Apr 16, 2026 · Added to CISA KEV catalog
  3. Apr 16, 2026 · Intel last updated
  4. Apr 30, 2026 · CISA remediation deadline

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 56 days ago
  • CVE.org· no data
  • FIRST EPSS· 56 days ago
  • CISA KEV· 46 days ago
  • OSV· 56 days ago

Listed in CISA KEV

Added 2026-04-16 · Remediation overdue by 95 days.

References

Unlock the full report

See how CVE-2026-34197 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.