Input validation error in ActiveMQ - CVE-2026-49434
Published: July 1, 2026
Vulnerability details
The vulnerability allows a remote user to instantiate denied transports inside the broker JVM and spawn a second BrokerService in the same JVM.
The vulnerability exists due to improper input validation in LdapNetworkConnector when processing LDAP entries that match the configured searchBase and searchFilter. A remote user can publish or modify matching LDAP entries to instantiate denied transports inside the broker JVM and spawn a second BrokerService in the same JVM.
Exploitation can be used to fetch an attacker-controlled URL.
Affected software
Jazz for Service Management
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-49434
Jazz for Service Management - update to 1.1.3.27 ifix 0002
activemq - update to 5.19.8-1
activemq-javadoc - update to 5.19.8-1