Code Injection in ActiveMQ - CVE-2026-41044
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation and code injection in the admin web console and DestinationView MBean when processing a malicious broker name and triggering VM transport creation. A remote user can construct a malicious broker name and send a message through the DestinationView MBean to execute arbitrary code.
Exploitation requires access to the admin web console and the DestinationView MBean exposed by Jolokia.
Affected software
Communications Unified Assurance
IBM Sterling Control Center
Bamboo Data Center
Bamboo Server
openEuler
activemq-javadoc
activemq
How to mitigate CVE-2026-41044
IBM Sterling Control Center - addressed in versions 6.3.1.0.9, 6.4.1.0.3, 6.4.2.0.4
Bamboo Data Center - addressed in versions 10.2.20, 12.1.8
Bamboo Server - addressed in versions 10.2.20, 12.1.8
activemq-javadoc - update to 5.19.6-1
activemq - update to 5.19.6-1
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache ActiveMQ
- openEuler 24.03 LTS SP3 update for activemq
- openEuler 24.03 LTS SP1 update for activemq
- openEuler 24.03 LTS update for activemq
- openEuler 22.03 LTS SP4 update for activemq
- Multiple vulnerabilities in IBM Control Center
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Bamboo Data Center