Threat reportVulnerabilityTL-2026-0386

CVE-2026-34197 — Apache ActiveMQ Jolokia Code Injection via Spring XML Context (CISA KEV)

highACTIVE

CVE-2026-34197 (TL-2026-0386), also tracked as ActiveMQ Jolokia XML Context Injection, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-04-17. It has no confirmed attribution, affects Apache ActiveMQ, references 1 CVE (CVE-2026-34197), maps to 26 MITRE ATT&CK techniques (T1027, T1036, T1046), and is covered by 9 detection rules and 28 indicators of compromise.

CVSS
8.8/10High
CVEs
1Referenced vulnerabilities
Techniques
26MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-0386

Threat ID
TL-2026-0386
Also known as
ActiveMQ Jolokia XML Context Injection, Spring XML Jolokia RCE
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
financial, government, technology, healthcare, manufacturing, telecommunications, logistics
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
28

Malware and tooling in CVE-2026-34197

Malware and tooling: Kinsing, xmrig, Cobalt Strike, Metasploit exploit/multi/http/activemq_jolokia_spring_rce (community module, 2026-04-11)

How CVE-2026-34197 works

Apache ActiveMQ's Jolokia JMX-HTTP bridge improperly validates discovery URIs, allowing an authenticated attacker to load attacker-controlled remote Spring XML contexts and achieve arbitrary code execution via bean factory methods such as Runtime.exec(). CISA added the flaw to the KEV catalog on 2026-04-16, confirming active exploitation in the wild. Affected versions: ActiveMQ < 5.19.4 and 6.0.0–6.2.2; patched in 5.19.4 and 6.2.3.

CVE-2026-34197 is a HIGH-severity (CVSS 8.8) code injection vulnerability in the Jolokia JMX-HTTP bridge bundled with Apache ActiveMQ's web console. The Jolokia servlet exposes management operations over HTTP/JSON, including a discovery mechanism that accepts a URI parameter used to bootstrap a Spring `ClassPathXmlApplicationContext` or `FileSystemXmlApplicationContext`. Input validation on that URI is insufficient: the servlet permits remote `http://` / `https://` / `ftp://` / `jar:` schemes and does not restrict the referenced XML to a safe schema. An authenticated attacker with access to the Jolokia endpoint (typically mounted at `/api/jolokia` on the ActiveMQ web admin console, port 8161) can supply a URI pointing at an attacker-controlled server that returns a malicious Spring bean definition. When ActiveMQ parses the XML, it instantiates beans defined in the document; Spring's `MethodInvokingFactoryBean` / `ProcessBuilder` / `Runtime.exec()` primitives allow attackers to spawn arbitrary OS processes as the ActiveMQ broker user.

The bug chain is analogous to the 2023-era CVE-2023-46604 OpenWire unmarshaller exploitation pattern but targets the management plane instead of the broker protocol. Because Jolokia is enabled by default in modern ActiveMQ 5.x and 6.x distributions and is frequently exposed to internal networks for monitoring, exploitation requires only broker admin credentials — which are routinely reused, left at defaults (`admin:admin`), or harvested from prior footholds. The default admin console authentication is HTTP Basic; environments that front-end the console with SSO or mTLS are not protected unless Jolokia itself is disabled or gated via `JolokiaAccessConfigurator` allow-lists.

Exploitation grants code execution at the ActiveMQ process privilege level, which on many deployments is a dedicated service account with read/write access to message queues and ActiveMQ configuration. Observed in-the-wild activity since early April 2026 includes crypto-miner deployment (XMRig variants), Cobalt Strike stager delivery, and at least one ransomware affiliate (tracked as `Storm-0914` by Microsoft Threat Intelligence; overlap with `FIN11`) using the vulnerability to pivot into data-center messaging infrastructure as a pre-encryption staging ground. CISA added CVE-2026-34197 to the Known Exploited Vulnerabilities catalog on 2026-04-16 with a federal civilian remediation deadline of 2026-04-30.

Apache published fixes on 2026-04-07 (one week before CISA KEV listing). ActiveMQ 5.19.4 and 6.2.3 restrict Jolokia discovery URIs to the `classpath:` scheme and require an administrator opt-in environment variable (`ACTIVEMQ_JOLOKIA_ALLOW_REMOTE_CONTEXTS=true`) to restore legacy behavior. Organizations that cannot patch immediately should disable the Jolokia servlet by removing `/api/jolokia/*` from `webapps/admin/WEB-INF/web.xml`, block inbound access to TCP/8161 at the perimeter, and monitor for Jolokia POST requests carrying `type=exec` operations referencing `spring:` or remote URIs.

MITRE ATT&CK techniques used in TL-2026-0386

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery

Execution

T1059 Command and Scripting Interpreter; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1106 Native API

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer

Initial Access

T1078.001 Valid Accounts: Default Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Credential Access

T1110.001 Brute Force: Password Guessing; T1552.001 Unsecured Credentials: Credentials In Files

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1496 Resource Hijacking

Persistence

T1505.003 Server Software Component: Web Shell; T1543 Create or Modify System Process

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1608.002 Stage Capabilities: Upload Tool

Reconnaissance

T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in CVE-2026-34197

  • Apache — ActiveMQ
    Vulnerable versions: < 5.19.4; 6.0.0 – 6.2.2
    Fixed in: 5.19.4; 6.2.3
  • Apache — ActiveMQ Broker
    Vulnerable versions: < 5.19.4; 6.0.0 – 6.2.2
    Fixed in: 5.19.4; 6.2.3
  • Apache — ActiveMQ Artemis (Jolokia integration shipped in distribution)
    Vulnerable versions: 2.33.0 – 2.36.0 when bundled Jolokia agent is enabled
    Fixed in: 2.37.0

Remediation for CVE-2026-34197

Patches

  • Apache ActiveMQ 5.19.4 (release 2026-04-07)
  • Apache ActiveMQ 6.2.3 (release 2026-04-07)

Immediate actions

  • Apply ActiveMQ 5.19.4 or 6.2.3 to all broker instances.
  • Block inbound access to the ActiveMQ web console port (default TCP/8161) at the network perimeter.
  • Rotate ActiveMQ admin console credentials; forbid default admin:admin.
  • Audit Jolokia access logs for POST requests containing 'type=exec', 'spring:', or remote URI references since 2026-03-15.

Workarounds

  • Remove /api/jolokia/* servlet mapping from webapps/admin/WEB-INF/web.xml and restart the broker.
  • Set ACTIVEMQ_JOLOKIA_ALLOW_REMOTE_CONTEXTS=false in the environment (default on patched versions).
  • Disable the ActiveMQ web admin console entirely by removing or commenting the web-console <import> in conf/activemq.xml.

Longer-term hardening

  • Disable the Jolokia servlet entirely if not required by monitoring tooling.
  • Enforce JolokiaAccessConfigurator allow-lists restricting MBean operations to read-only views for monitoring principals.
  • Place ActiveMQ brokers behind an authenticated reverse proxy that enforces mTLS for management plane access.
  • Deploy host-based EDR to ActiveMQ hosts to catch post-exploitation tooling (XMRig, Cobalt Strike, PowerShell).
  • Segment messaging infrastructure from user/workstation VLANs to contain lateral movement.
  • Subscribe to the activemq-users mailing list and Apache CVE feed for future advisories.

CVEs associated with CVE-2026-34197

CVE-2026-34197

Weaknesses (CWE) in CVE-2026-34197

CWE-20, CWE-94, CWE-913, CWE-502

Timeline of CVE-2026-34197

  • Independent researcher at NCC Group identifies insufficient URI validation in the Jolokia discovery handler during a routine audit of ActiveMQ 6.2.1.
  • Vulnerability privately reported to the Apache Security Team via security@activemq.apache.org with a working PoC demonstrating remote Spring XML context loading.
  • Apache Security Team acknowledges the report, assigns tracking ID, and begins coordinating a fix for the 5.x and 6.x branches.
  • MITRE assigns CVE-2026-34197 to the Jolokia Spring XML context code injection issue.
  • NVD publishes CVE-2026-34197 with CVSS 3.1 base score 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
  • Apache publishes ActiveMQ 5.19.4 and 6.2.3 fixing CVE-2026-34197. Security advisory posted on activemq.apache.org.
  • Shadowserver and GreyNoise detect opportunistic scanning for /api/jolokia endpoints and version fingerprinting POSTs against Internet-exposed ActiveMQ consoles.
  • Public proof-of-concept exploit published on GitHub (HackerOne advisory GHSA-cve-2026-34197) demonstrating full RCE via Jolokia discovery URI.
  • Microsoft Threat Intelligence observes Storm-0914 deploying XMRig and Cobalt Strike stagers via CVE-2026-34197 exploitation against manufacturing and logistics ActiveMQ brokers.
  • Microsoft publishes public threat intelligence blog tying Storm-0914 activity to pre-ransomware staging targeting ActiveMQ messaging infrastructure.
  • CISA adds CVE-2026-34197 to the Known Exploited Vulnerabilities catalog with a federal civilian remediation due date of 2026-04-30.
  • Threadlinqs Intelligence publishes TL-2026-0386 with full MITRE mapping, IOCs, detection coverage, and simulation.
  • As of 2026-05-29, CVE-2026-34197 (ActiveMQ Jolokia RCE) remains an active threat: it is in CISA KEV with confirmed in-the-wild exploitation and 6,000+ internet-exposed vulnerable instances despite Apache patches. Effectively unauthenticated on v6.0.0-6.1.1 via CVE-2024-32114, so patch/exposure reduction stays urgent.

Sources cited for CVE-2026-34197

Detection coverage for TL-2026-0386

As of 2026-04-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0386 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats