Code Injection in ActiveMQ - CVE-2026-42588
Published: June 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to code injection in the Jolokia JMX-HTTP bridge addNetworkConnector operation when processing a crafted discovery URI through /api/jolokia/. A remote user can invoke BrokerService.addNetworkConnector(String) with a crafted discovery URI to execute arbitrary code.
The issue involves loading a Spring XML application context via the VM transport's brokerConfig parameter using a "masterslave://" URL, and user interaction is not required.
Affected software
Bamboo Data Center
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-42588
Bamboo Data Center - addressed in versions 10.2.21, 12.1.9
activemq - update to 5.19.7-1
activemq-javadoc - update to 5.19.7-1