Code Injection in ActiveMQ - CVE-2026-42588
Published: June 4, 2026
ActiveMQ
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to code injection in the Jolokia JMX-HTTP bridge addNetworkConnector operation when processing a crafted discovery URI through /api/jolokia/. A remote user can invoke BrokerService.addNetworkConnector(String) with a crafted discovery URI to execute arbitrary code.
The issue involves loading a Spring XML application context via the VM transport's brokerConfig parameter using a "masterslave://" URL, and user interaction is not required.