Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

CVE-2026-34197: Apache ActiveMQ Jolokia API Remote Code Execution

Дата публикации: 24-08-2026 08:07:46

Apache ActiveMQ Classic contains a high-impact vulnerability that affects versions before 5.19.4 and versions 6.0.0 through 6.2.2. An authenticated user can misuse Jolokia, the web console’s management interface, to monitor and control the broker, which functions as the central messaging service. By submitting specially crafted URIs, an attacker can abuse broker management functions to execute malicious commands and potentially achieve remote code execution. This vulnerability has been assigned CVE-2026-34197. More details about affected versions and references are available at NVD.
Apache ActiveMQ Classic is a Java Message Service (JMS)-based broker that supports asynchronous publish/subscribe and queue-based messaging. Producers send messages to the broker, while consumers receive them through topics or queues.
This article analyzes CVE-2026-34197, the vulnerable code path, affected versions, and detection considerations.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CVE-2026-34486: Apache Tomcat Tribes Unauthenticated RCE07.4725-08-2026
2CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS07.4113-08-2026
3CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for011.5413-08-2026
4GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability 06.9719-08-2026
5Critical NGINX Vulnerability CVE-2026-42945: What Linux Admins Should Check Now-5718-05-2026
6Oracle Security Alert Advisory - CVE-2026-35273 01011-06-2026
7Fixes available for CVE-2026-31431 (Copy Fail) Linux Kernel Local Privilege Escalation Vulnerability07.8401-05-2026
8Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands04.7128-07-2026
9Security advisory: CVE-2026-9740 and CVE-2026-11933 in Percona Server for MongoDB06.5517-06-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 10.34. Источник: community.hpe.com.