Skip to main content

CVE detail

CVE-2026-34197

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue

CVSS 8.8 · HighBuzz score 86.0KEV listed2 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 86.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 11.1
Mention score
30.0
19 evidence mentions in the snapshot
Diversity score
20.0
12 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
11.1
2 repos · best confidence 0.99
Best PoC traction
3
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
1
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
19 source links · newest first
  • ity matters. They’ve built their reputation on finding the ones that do. This year, their AI-assisted research surfaced CVE-2026-34197, a remote code execution vulnerability in a widely deployed open-source message broker, and CVE-2026-48558, a critical authentication bypass in a remote monitoring and management platform. Both landed on CISA’s KEV Cata

    exploithorizon3.aiJul 15, 2026, 12:15 PM
  • AI Threat Landscape Digest March-April 2026Check Point Research

    earchers identified an exposed operator server. Bissa is a modular mass-exploitation platform built around React2Shell (CVE-2025-55182), with 900+ confirmed compromises across millions of scanned Next.js endpoints and an archive of 30,000+ distinct .env filenames recovered from operator-controlled S3 storage. The operation has been running since Septem

    vendorresearch.checkpoint.comMay 26, 2026, 10:09 AM
  • Mythos shows how vulnerabilities become real risk—by chaining into attack paths that lead to impact.

    exploithorizon3.aiApr 22, 2026, 6:38 PM
  • Two weeks after researchers using an AI tool discovered a major hole in Apache’s ActiveMQ messaging middleware, there are still thousands of unpatched instances open to the internet, more evidence that many application developers and IT leaders aren’t paying close attention to warnings about vulnerabilities. While the remote code injection vulnerability [CVE-2026-34197] was revealed on […]

    newswww.csoonline.comApr 21, 2026, 8:28 PM
  • 20th April – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 20th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Booking.com, the Amsterdam-based travel platform, has confirmed a data breach after unauthorized parties accessed reservation data linked to some customers. Exposed information included names, email addresses, phone numbers, physical addresses, and booking […]

    vendorresearch.checkpoint.comApr 20, 2026, 2:24 PM
  • The remote code execution vulnerability tracked as CVE-2026-34197 came to light in early April.

    newswww.securityweek.comApr 17, 2026, 9:50 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Apache ActiveMQ to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in Apache ActiveMQ, tracked as CVE-2026-34197 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-34197 is a critical flaw in Apache ActiveMQ caused by […]

    newssecurityaffairs.comApr 17, 2026, 7:39 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Cloudflare moves up its post-quantum deadline as researchers narrow the path to Q-Day Cloudflare announced it is targeting 2029 to complete post-quantum security across its entire product suite, including post-quantum authentication. The company is following a revised roadmap that Google also adopted after announcing that it had improved the quantum algorithm used to break elliptic curve cryptography. Google stopped short … More →

    newswww.helpnetsecurity.comApr 12, 2026, 8:00 AM
  • Anthropic’s Claude dug up a critical remote code execution (RCE) bug that sat quietly inside Apache ActiveMQ Classic for over a decade. Researchers at Horizon3.ai say that it only took minutes for their team to work out an exploit chain for the bug with the help of AI. The researcher behind the work, Naveen Sunkavally, […]

    newswww.csoonline.comApr 10, 2026, 11:39 AM
  • In the latest demonstration of how AI assistants can help with bug hunting, Horizon3.ai researcher Naveen Sunkavally used Claude to unearth CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ that’s been introduced in the codebase 13 years ago. The vulnerability was patched in late March 2026 and there’s currently no indication that it is being actively exploited by attackers. Neveretheless, with ActiveMQ vulnerabilities having been previously leveraged for ransomware and malware attacks, organizations should … More →

    newswww.helpnetsecurity.comApr 9, 2026, 1:04 PM
  • The vulnerability requires authentication for successful exploitation, but another flaw exposes the Jolokia API without authentication.

    newswww.securityweek.comApr 8, 2026, 2:30 PM
  • CVE-2026-34197 enables remote code execution in ActiveMQ via Jolokia. Exploitation chains VM transport and remote config loading.

    exploithorizon3.aiApr 7, 2026, 7:32 PM
  • CVE-2026-34197Horizon3.ai

    CVE-2026-34197 allows code execution in ActiveMQ via Jolokia. Validate exposure, patch affected versions, and confirm remediation.

    exploithorizon3.aiApr 7, 2026, 7:30 PM
  • No excerpt available.

    Mitigationwww.cisa.govApr 7, 2026, 9:16 AM
  • https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34197.jsonsecurity.access.redhat.com

    No excerpt available.

    Vendor Advisorysecurity.access.redhat.comApr 7, 2026, 9:16 AM
  • https://bugzilla.redhat.com/show_bug.cgi?id=2455869bugzilla.redhat.com

    No excerpt available.

    Exploitbugzilla.redhat.comApr 7, 2026, 9:16 AM
  • No excerpt available.

    Vendor Advisoryaccess.redhat.comApr 7, 2026, 9:16 AM
  • No excerpt available.

    Exploitwww.openwall.comApr 7, 2026, 9:16 AM
  • No excerpt available.

    Vendor Advisoryactivemq.apache.orgApr 7, 2026, 9:16 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

2 repository references · best confidence 0.99 · max 3 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence