Apache ActiveMQ < 5.19.7 / 6.x < 6.2.6 Multiple Vulnerabilities

high Nessus Plugin ID 318667

Synopsis

The remote host is running a web application that is affected by multiple vulnerabilities.

Description

The version of Apache ActiveMQ running on the remote host is prior to 5.19.7 or 6.x prior to 6.2.6. It is, therefore, affected by multiple vulnerabilities:

- Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as masterslave:vm://...,... and static:vm://... incorrectly pass validation allowing bypass of fix in CVE-2026-34197. An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). (CVE-2026-45505)

- Incomplete authorization by Apache ActiveMQ server allows authenticated connections to remove existing destinations with proper permissions. (CVE-2026-46605)

- Incorrect Default Permissions vulnerability in Apache ActiveMQ. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue and removeQueue. (CVE-2026-49157)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Apache ActiveMQ version 5.19.7, 6.2.6, or later.

See Also

http://www.nessus.org/u?a28095d0

http://www.nessus.org/u?2908cc8c

http://www.nessus.org/u?a61553df

Plugin Details

Severity: High

ID: 318667

File Name: activemq_6_2_6.nasl

Version: 1.1

Type: Combined

Agent: unix

Family: CGI abuses

Published: 6/4/2026

Updated: 6/4/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Enable CGI Scanning: true

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-45505

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:apache:activemq

Required KB Items: installed_sw/Apache ActiveMQ

Patch Publication Date: 5/31/2026

Vulnerability Publication Date: 5/31/2026

Reference Information

CVE: CVE-2026-45505, CVE-2026-46605, CVE-2026-49157