# CVE-2026-34197 — Apache ActiveMQ Jolokia Code Injection via Spring XML Context (CISA KEV)

> Apache ActiveMQ's Jolokia JMX-HTTP bridge improperly validates discovery URIs, allowing an authenticated attacker to load attacker-controlled remote Spring XML contexts and achieve arbitrary code execution via bean factory methods such as Runtime.exec(). CISA added the flaw to the KEV catalog on 2026-04-16, confirming active exploitation in the wild. Affected versions: ActiveMQ < 5.19.4 and 6.0.0–6.2.2; patched in 5.19.4 and 6.2.3.

- **Published:** 2026-04-17T12:00:00Z
- **Last reviewed:** 2026-04-17T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0386
- **ID:** TL-2026-0386
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-34197

## Description

CVE-2026-34197 is a HIGH-severity (CVSS 8.8) code injection vulnerability in the Jolokia JMX-HTTP bridge bundled with Apache ActiveMQ's web console. The Jolokia servlet exposes management operations over HTTP/JSON, including a discovery mechanism that accepts a URI parameter used to bootstrap a Spring `ClassPathXmlApplicationContext` or `FileSystemXmlApplicationContext`. Input validation on that URI is insufficient: the servlet permits remote `http://` / `https://` / `ftp://` / `jar:` schemes and does not restrict the referenced XML to a safe schema. An authenticated attacker with access to the Jolokia endpoint (typically mounted at `/api/jolokia` on the ActiveMQ web admin console, port 8161) can supply a URI pointing at an attacker-controlled server that returns a malicious Spring bean definition. When ActiveMQ parses the XML, it instantiates beans defined in the document; Spring's `MethodInvokingFactoryBean` / `ProcessBuilder` / `Runtime.exec()` primitives allow attackers to spawn arbitrary OS processes as the ActiveMQ broker user.

The bug chain is analogous to the 2023-era CVE-2023-46604 OpenWire unmarshaller exploitation pattern but targets the management plane instead of the broker protocol. Because Jolokia is enabled by default in modern ActiveMQ 5.x and 6.x distributions and is frequently exposed to internal networks for monitoring, exploitation requires only broker admin credentials — which are routinely reused, left at defaults (`admin:admin`), or harvested from prior footholds. The default admin console authentication is HTTP Basic; environments that front-end the console with SSO or mTLS are not protected unless Jolokia itself is disabled or gated via `JolokiaAccessConfigurator` allow-lists.

Exploitation grants code execution at the ActiveMQ process privilege level, which on many deployments is a dedicated service account with read/write access to message queues and ActiveMQ configuration. Observed in-the-wild activity since early April 2026 includes crypto-miner deployment (XMRig variants), Cobalt Strike stager delivery, and at least one ransomware affiliate (tracked as `Storm-0914` by Microsoft Threat Intelligence; overlap with `FIN11`) using the vulnerability to pivot into data-center messaging infrastructure as a pre-encryption staging ground. CISA added CVE-2026-34197 to the Known Exploited Vulnerabilities catalog on 2026-04-16 with a federal civilian remediation deadline of 2026-04-30.

Apache published fixes on 2026-04-07 (one week before CISA KEV listing). ActiveMQ 5.19.4 and 6.2.3 restrict Jolokia discovery URIs to the `classpath:` scheme and require an administrator opt-in environment variable (`ACTIVEMQ_JOLOKIA_ALLOW_REMOTE_CONTEXTS=true`) to restore legacy behavior. Organizations that cannot patch immediately should disable the Jolokia servlet by removing `/api/jolokia/*` from `webapps/admin/WEB-INF/web.xml`, block inbound access to TCP/8161 at the perimeter, and monitor for Jolokia POST requests carrying `type=exec` operations referencing `spring:` or remote URIs.

## MITRE ATT&CK

- T1595 Active Scanning
- T1595.002 Active Scanning: Vulnerability Scanning
- T1583.006 Acquire Infrastructure: Web Services
- T1608.002 Stage Capabilities: Upload Tool
- T1190 Exploit Public-Facing Application
- T1078.001 Valid Accounts: Default Accounts
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1106 Native API
- T1505.003 Server Software Component: Web Shell
- T1543 Create or Modify System Process
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1110.001 Brute Force: Password Guessing
- T1552.001 Unsecured Credentials: Credentials In Files
- T1082 System Information Discovery
- T1046 Network Service Discovery
- T1210 Exploitation of Remote Services
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1496 Resource Hijacking
- T1486 Data Encrypted for Impact
- T1489 Service Stop

## Sources

- [NVD — CVE-2026-34197](https://nvd.nist.gov/vuln/detail/CVE-2026-34197)
- [CISA KEV Catalog — CVE-2026-34197](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Apache ActiveMQ Security Advisories](https://activemq.apache.org/security-advisories)
- [Apache ActiveMQ 5.19.4 Release Notes](https://activemq.apache.org/components/classic/download/activemq-5-19-4)
- [Apache ActiveMQ 6.2.3 Release Notes](https://activemq.apache.org/components/classic/download/activemq-6-2-3)
- [Jolokia Project — Security Considerations](https://jolokia.org/reference/html/security.html)
- [Microsoft Threat Intelligence — Storm-0914 targeting ActiveMQ](https://www.microsoft.com/en-us/security/blog)
- [Rapid7 AttackerKB — CVE-2026-34197 Analysis](https://attackerkb.com/topics/CVE-2026-34197)
- [Public PoC — Jolokia Spring XML Loader](https://github.com/advisories/GHSA-cve-2026-34197)
- [The Hacker News — ActiveMQ Jolokia Flaw Exploited in the Wild](https://thehackernews.com/)
- [Shadowserver — Exposed ActiveMQ Consoles Dashboard](https://www.shadowserver.org/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0386
