Threat reportVulnerabilityTL-2026-0386
CVE-2026-34197 — Apache ActiveMQ Jolokia Code Injection via Spring XML Context (CISA KEV)
CVE-2026-34197 (TL-2026-0386), also tracked as ActiveMQ Jolokia XML Context Injection, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-04-17. It has no confirmed attribution, affects Apache ActiveMQ, references 1 CVE (CVE-2026-34197), maps to 26 MITRE ATT&CK techniques (T1027, T1036, T1046), and is covered by 9 detection rules and 28 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 26MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-0386
- Threat ID
- TL-2026-0386
- Also known as
- ActiveMQ Jolokia XML Context Injection, Spring XML Jolokia RCE
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- financial, government, technology, healthcare, manufacturing, telecommunications, logistics
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in CVE-2026-34197
Malware and tooling: Kinsing, xmrig, Cobalt Strike, Metasploit exploit/multi/http/activemq_jolokia_spring_rce (community module, 2026-04-11)
How CVE-2026-34197 works
Apache ActiveMQ's Jolokia JMX-HTTP bridge improperly validates discovery URIs, allowing an authenticated attacker to load attacker-controlled remote Spring XML contexts and achieve arbitrary code execution via bean factory methods such as Runtime.exec(). CISA added the flaw to the KEV catalog on 2026-04-16, confirming active exploitation in the wild. Affected versions: ActiveMQ < 5.19.4 and 6.0.0–6.2.2; patched in 5.19.4 and 6.2.3.
CVE-2026-34197 is a HIGH-severity (CVSS 8.8) code injection vulnerability in the Jolokia JMX-HTTP bridge bundled with Apache ActiveMQ's web console. The Jolokia servlet exposes management operations over HTTP/JSON, including a discovery mechanism that accepts a URI parameter used to bootstrap a Spring `ClassPathXmlApplicationContext` or `FileSystemXmlApplicationContext`. Input validation on that URI is insufficient: the servlet permits remote `http://` / `https://` / `ftp://` / `jar:` schemes and does not restrict the referenced XML to a safe schema. An authenticated attacker with access to the Jolokia endpoint (typically mounted at `/api/jolokia` on the ActiveMQ web admin console, port 8161) can supply a URI pointing at an attacker-controlled server that returns a malicious Spring bean definition. When ActiveMQ parses the XML, it instantiates beans defined in the document; Spring's `MethodInvokingFactoryBean` / `ProcessBuilder` / `Runtime.exec()` primitives allow attackers to spawn arbitrary OS processes as the ActiveMQ broker user.
The bug chain is analogous to the 2023-era CVE-2023-46604 OpenWire unmarshaller exploitation pattern but targets the management plane instead of the broker protocol. Because Jolokia is enabled by default in modern ActiveMQ 5.x and 6.x distributions and is frequently exposed to internal networks for monitoring, exploitation requires only broker admin credentials — which are routinely reused, left at defaults (`admin:admin`), or harvested from prior footholds. The default admin console authentication is HTTP Basic; environments that front-end the console with SSO or mTLS are not protected unless Jolokia itself is disabled or gated via `JolokiaAccessConfigurator` allow-lists.
Exploitation grants code execution at the ActiveMQ process privilege level, which on many deployments is a dedicated service account with read/write access to message queues and ActiveMQ configuration. Observed in-the-wild activity since early April 2026 includes crypto-miner deployment (XMRig variants), Cobalt Strike stager delivery, and at least one ransomware affiliate (tracked as `Storm-0914` by Microsoft Threat Intelligence; overlap with `FIN11`) using the vulnerability to pivot into data-center messaging infrastructure as a pre-encryption staging ground. CISA added CVE-2026-34197 to the Known Exploited Vulnerabilities catalog on 2026-04-16 with a federal civilian remediation deadline of 2026-04-30.
Apache published fixes on 2026-04-07 (one week before CISA KEV listing). ActiveMQ 5.19.4 and 6.2.3 restrict Jolokia discovery URIs to the `classpath:` scheme and require an administrator opt-in environment variable (`ACTIVEMQ_JOLOKIA_ALLOW_REMOTE_CONTEXTS=true`) to restore legacy behavior. Organizations that cannot patch immediately should disable the Jolokia servlet by removing `/api/jolokia/*` from `webapps/admin/WEB-INF/web.xml`, block inbound access to TCP/8161 at the perimeter, and monitor for Jolokia POST requests carrying `type=exec` operations referencing `spring:` or remote URIs.
MITRE ATT&CK techniques used in TL-2026-0386
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1106 Native API
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Initial Access
T1078.001 Valid Accounts: Default Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Credential Access
T1110.001 Brute Force: Password Guessing; T1552.001 Unsecured Credentials: Credentials In Files
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1496 Resource Hijacking
Persistence
T1505.003 Server Software Component: Web Shell; T1543 Create or Modify System Process
Resource Development
T1583.006 Acquire Infrastructure: Web Services; T1608.002 Stage Capabilities: Upload Tool
Reconnaissance
T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning
Affected products and versions in CVE-2026-34197
- Apache — ActiveMQ
Vulnerable versions: < 5.19.4; 6.0.0 – 6.2.2
Fixed in: 5.19.4; 6.2.3 - Apache — ActiveMQ Broker
Vulnerable versions: < 5.19.4; 6.0.0 – 6.2.2
Fixed in: 5.19.4; 6.2.3 - Apache — ActiveMQ Artemis (Jolokia integration shipped in distribution)
Vulnerable versions: 2.33.0 – 2.36.0 when bundled Jolokia agent is enabled
Fixed in: 2.37.0
Remediation for CVE-2026-34197
Patches
- Apache ActiveMQ 5.19.4 (release 2026-04-07)
- Apache ActiveMQ 6.2.3 (release 2026-04-07)
Immediate actions
- Apply ActiveMQ 5.19.4 or 6.2.3 to all broker instances.
- Block inbound access to the ActiveMQ web console port (default TCP/8161) at the network perimeter.
- Rotate ActiveMQ admin console credentials; forbid default admin:admin.
- Audit Jolokia access logs for POST requests containing 'type=exec', 'spring:', or remote URI references since 2026-03-15.
Workarounds
- Remove /api/jolokia/* servlet mapping from webapps/admin/WEB-INF/web.xml and restart the broker.
- Set ACTIVEMQ_JOLOKIA_ALLOW_REMOTE_CONTEXTS=false in the environment (default on patched versions).
- Disable the ActiveMQ web admin console entirely by removing or commenting the web-console <import> in conf/activemq.xml.
Longer-term hardening
- Disable the Jolokia servlet entirely if not required by monitoring tooling.
- Enforce JolokiaAccessConfigurator allow-lists restricting MBean operations to read-only views for monitoring principals.
- Place ActiveMQ brokers behind an authenticated reverse proxy that enforces mTLS for management plane access.
- Deploy host-based EDR to ActiveMQ hosts to catch post-exploitation tooling (XMRig, Cobalt Strike, PowerShell).
- Segment messaging infrastructure from user/workstation VLANs to contain lateral movement.
- Subscribe to the activemq-users mailing list and Apache CVE feed for future advisories.
CVEs associated with CVE-2026-34197
Weaknesses (CWE) in CVE-2026-34197
Timeline of CVE-2026-34197
- Independent researcher at NCC Group identifies insufficient URI validation in the Jolokia discovery handler during a routine audit of ActiveMQ 6.2.1.
- Vulnerability privately reported to the Apache Security Team via security@activemq.apache.org with a working PoC demonstrating remote Spring XML context loading.
- Apache Security Team acknowledges the report, assigns tracking ID, and begins coordinating a fix for the 5.x and 6.x branches.
- MITRE assigns CVE-2026-34197 to the Jolokia Spring XML context code injection issue.
- NVD publishes CVE-2026-34197 with CVSS 3.1 base score 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Apache publishes ActiveMQ 5.19.4 and 6.2.3 fixing CVE-2026-34197. Security advisory posted on activemq.apache.org.
- Shadowserver and GreyNoise detect opportunistic scanning for /api/jolokia endpoints and version fingerprinting POSTs against Internet-exposed ActiveMQ consoles.
- Public proof-of-concept exploit published on GitHub (HackerOne advisory GHSA-cve-2026-34197) demonstrating full RCE via Jolokia discovery URI.
- Microsoft Threat Intelligence observes Storm-0914 deploying XMRig and Cobalt Strike stagers via CVE-2026-34197 exploitation against manufacturing and logistics ActiveMQ brokers.
- Microsoft publishes public threat intelligence blog tying Storm-0914 activity to pre-ransomware staging targeting ActiveMQ messaging infrastructure.
- CISA adds CVE-2026-34197 to the Known Exploited Vulnerabilities catalog with a federal civilian remediation due date of 2026-04-30.
- Threadlinqs Intelligence publishes TL-2026-0386 with full MITRE mapping, IOCs, detection coverage, and simulation.
- As of 2026-05-29, CVE-2026-34197 (ActiveMQ Jolokia RCE) remains an active threat: it is in CISA KEV with confirmed in-the-wild exploitation and 6,000+ internet-exposed vulnerable instances despite Apache patches. Effectively unauthenticated on v6.0.0-6.1.1 via CVE-2024-32114, so patch/exposure reduction stays urgent.
Sources cited for CVE-2026-34197
- NVD — CVE-2026-34197
- CISA KEV Catalog — CVE-2026-34197
- Apache ActiveMQ Security Advisories
- Apache ActiveMQ 5.19.4 Release Notes
- Apache ActiveMQ 6.2.3 Release Notes
- Jolokia Project — Security Considerations
- Microsoft Threat Intelligence — Storm-0914 targeting ActiveMQ
- Rapid7 AttackerKB — CVE-2026-34197 Analysis
- Public PoC — Jolokia Spring XML Loader
- The Hacker News — ActiveMQ Jolokia Flaw Exploited in the Wild
- Shadowserver — Exposed ActiveMQ Consoles Dashboard
Detection coverage for TL-2026-0386
As of 2026-04-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0386 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.