Code Injection in ActiveMQ - CVE-2026-40466
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation and code injection in BrokerView.addNetworkConnector and BrokerView.addConnector through Jolokia when adding a connector using an HTTP discovery transport. A remote user can add a connector that causes a malicious HTTP endpoint to return a VM transport and load a remote Spring XML application context to execute arbitrary code.
Exploitation requires the activemq-http module to be on the classpath.
Affected software
IBM Sterling Control Center
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-40466
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
activemq - update to 5.19.6-1
activemq-javadoc - update to 5.19.6-1