Code Injection in ActiveMQ - CVE-2026-41044

 

Code Injection in ActiveMQ - CVE-2026-41044

Published: April 28, 2026


Vulnerability identifier: #VU128313
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41044
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper input validation and code injection in the admin web console and DestinationView MBean when processing a malicious broker name and triggering VM transport creation. A remote user can construct a malicious broker name and send a message through the DestinationView MBean to execute arbitrary code.

Exploitation requires access to the admin web console and the DestinationView MBean exposed by Jolokia.


Affected software

ActiveMQ
Communications Unified Assurance
IBM Sterling Control Center
Bamboo Data Center
Bamboo Server
openEuler
activemq-javadoc
activemq

How to mitigate CVE-2026-41044

Install security update from vendor's website.

ActiveMQ - addressed in versions 5.19.6, 6.2.5
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
Bamboo Data Center - addressed in versions 10.2.20, 12.1.8
Bamboo Server - addressed in versions 10.2.20, 12.1.8
activemq-javadoc - update to 5.19.6-1
activemq - update to 5.19.6-1

External References

Related Security Bulletins