https://seclists.org/oss-sec/2026/q2/24: CVE-2026-34197: Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Published Apr 6, 2026
·Updated
Affected Software
2 affected components
maven/org.apache.activemq/activemq-broker<5.19.4, >=6.0.0<6.2.3
maven/org.apache.activemq/activemq-all<5.19.4, >=6.0.0<6.2.3
Frequently Asked Questions
1
What is the severity of CVE-2026-34197?
The severity of CVE-2026-34197 is classified as important.
2
Which versions of Apache ActiveMQ are affected by CVE-2026-34197?
CVE-2026-34197 affects Apache ActiveMQ Broker versions before 5.19.4, and 6.0.0 versions before 6.2.3, as well as Apache ActiveMQ versions before 5.19.4.
3
How do I fix CVE-2026-34197?
To fix CVE-2026-34197, upgrade to Apache ActiveMQ Broker version 5.19.4 or later, or Apache ActiveMQ version 6.2.3 or later.
4
What type of attack does CVE-2026-34197 allow?
CVE-2026-34197 allows authenticated users to perform remote code execution (RCE) via Jolokia MBeans.
5
When was CVE-2026-34197 published?
CVE-2026-34197 was published on April 6, 2026.