# Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge (CVE-2026-34197)

> A 13-year-old code injection vulnerability in Apache ActiveMQ Classic allows authenticated attackers to achieve remote code execution through the Jolokia JMX-HTTP bridge by invoking addNetworkConnector with a crafted VM transport URI that loads malicious Spring XML configuration. On versions 6.0.0-6.1.1, the flaw is effectively unauthenticated due to CVE-2024-32114.

- **Published:** 2026-04-08T12:00:00Z
- **Last reviewed:** 2026-04-08T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0337
- **ID:** TL-2026-0337
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-34197

## Description

CVE-2026-34197 is a critical remote code execution vulnerability in Apache ActiveMQ Classic that has existed undetected for approximately 13 years. The vulnerability resides in the interaction between ActiveMQ''s Jolokia JMX-HTTP bridge, the broker''s network connector management API, and Spring Framework''s XML application context loading mechanism.

Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console (default port 8161). Following the patch for CVE-2022-41678, which restricted dangerous JDK MBeans, the Jolokia security policy was configured to permit exec operations on all ActiveMQ MBeans (org.apache.activemq:*). This overly permissive allowlist enables invocation of BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String) through the Jolokia REST API.

The exploit chain works as follows: An attacker sends an HTTP POST request to the /api/jolokia/ endpoint, invoking the addNetworkConnector operation on the broker MBean with a specially crafted VM transport URI. The URI contains a brokerConfig=xbean:http:// parameter pointing to an attacker-controlled server hosting a malicious Spring XML configuration file. When ActiveMQ processes the vm:// URI referencing a non-existent broker, it automatically attempts to instantiate a new embedded broker by calling BrokerFactory.createBroker() with the attacker-supplied URL. The xbean: scheme delegates to Spring''s ResourceXmlApplicationContext, which fetches the remote XML file and instantiates all singleton bean definitions — including beans configured to execute arbitrary OS commands via Spring''s MethodInvokingFactoryBean calling Runtime.exec().

Critically, Spring''s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, meaning code execution occurs regardless of whether the broker configuration is ultimately valid. This makes exploitation reliable and deterministic.

The vulnerability requires Jolokia authentication, but default credentials (admin:admin) are extremely common in production deployments. On ActiveMQ versions 6.0.0 through 6.1.1, the vulnerability is effectively unauthenticated because CVE-2024-32114 inadvertently exposed the Jolokia API without access control, eliminating the authentication barrier entirely.

The vulnerability was discovered by Naveen Sunkavally of Horizon3.ai using Anthropic''s Claude AI model, which identified the exploit chain in approximately 10 minutes by connecting multiple seemingly benign features into a viable attack path. As Sunkavally noted, ''Each feature in isolation does what it''s supposed to, but they were dangerous together. This is exactly where Claude shone.'' The discovery was described as ''80% Claude with 20% gift-wrapping by a human.''

Apache ActiveMQ has a history of severe RCE vulnerabilities that have been actively exploited in the wild, including CVE-2023-46604 (unauthenticated RCE on the broker port, exploited by ransomware groups and listed in CISA KEV) and CVE-2016-3088 (authenticated web console RCE, also in CISA KEV). Given this pattern, CVE-2026-34197 presents significant risk for mass exploitation, particularly against internet-exposed ActiveMQ instances with default credentials.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1505 Server Software Component
- T1078 Valid Accounts
- T1211 Exploitation for Stealth
- T1548 Abuse Elevation Control Mechanism
- T1110 Brute Force
- T1046 Network Service Discovery
- T1210 Exploitation of Remote Services
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1489 Service Stop

## Sources

- [Horizon3.ai Disclosure — CVE-2026-34197 ActiveMQ RCE via Jolokia API](https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/)
- [Horizon3.ai Vulnerability Analysis — CVE-2026-34197](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-34197/)
- [Apache ActiveMQ Security Advisory — CVE-2026-34197](https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt)
- [BleepingComputer — 13-year-old bug in ActiveMQ lets hackers remotely execute commands](https://www.bleepingcomputer.com/news/security/13-year-old-bug-in-activemq-lets-hackers-remotely-execute-commands/)
- [CVE Record — CVE-2026-34197](https://www.cve.org/CVERecord?id=CVE-2026-34197)
- [GBHackers — Claude Identifies Critical 13-Year-Old RCE Vulnerability](https://gbhackers.com/claude-identifies-critical-13-year-old-rce-vulnerability-in-apache-activemq/)
- [CyberSecurityNews — Claude Finds 13-Year-Old 0-Day RCE in Apache ActiveMQ](https://cybersecuritynews.com/claude-apache-activemq/)
- [CVEFeed — CVE-2026-34197 Detail](https://cvefeed.io/vuln/detail/CVE-2026-34197)
- [OSS-Security Mailing List — CVE-2026-34197 Notification](http://www.openwall.com/lists/oss-security/2026/04/06/3)
- [Infosecurity Magazine — Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years](https://www.infosecurity-magazine.com/news/claude-apache-activemq-bug-hidden/)
- [Apache ActiveMQ Classic Security Advisories](https://activemq.apache.org/components/classic/security)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0337
