SCA: security update for org.apache.activemq:activemq-all, org.apache.activemq:activemq-broker, org.apache.activemq:apache-activemq (GHSA-w3w2-mpp5-92gm)

high Tenable Cloud Security Plugin ID 441137

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix
in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via
BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia if the activemq-http module is
on the classpath. A malicious HTTP endpoint can return a VM transport through the HTTP URI which will
bypass the validation added in CVE-2026-34197. The attacker can then use the VM transport's brokerConfig
parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because
Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates
the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such
as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.6, from 6.0.0 before 6.2.5;
Apache ActiveMQ All: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ: before 5.19.6, from 6.0.0
before 6.2.5. Users are recommended to upgrade to version 5.19.6 or 6.2.5, which fixes the issue.
(CVE-2026-40466)

Solution

Update the org.apache.activemq:activemq-all library and its related packages to version 5.19.6 or later.

See Also

https://github.com/advisories/GHSA-w3w2-mpp5-92gm

Plugin Details

Severity: High

ID: 441137

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 5/5/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.03

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-40466

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/24/2026

Vulnerability Publication Date: 4/24/2026

Reference Information

CVE: CVE-2026-40466