Code Injection Vulnerability in Apache ActiveMQ by Apache
CVE-2026-40466
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 24 April 2026
What is CVE-2026-40466?
A vulnerability in Apache ActiveMQ allows an authenticated attacker to exploit improper input validation, enabling code injection through the HTTP Discovery transport. This issue can be triggered if the activemq-http module is present on the classpath. Attackers can leverage this flaw by configuring a malicious HTTP endpoint to return a VM transport, circumventing previous security measures. This enables them to execute remote code on the broker's JVM via the brokerConfig parameter, posing significant risks of arbitrary code execution. Users are urged to upgrade to the specified versions to mitigate this risk.
Affected Version(s)
Apache ActiveMQ 0 < 5.19.6
Apache ActiveMQ 6.0.0 < 6.2.5
Apache ActiveMQ All 0 < 5.19.6