Code Injection Vulnerability in Apache ActiveMQ by Apache
CVE-2026-40466

8.8HIGH

What is CVE-2026-40466?

A vulnerability in Apache ActiveMQ allows an authenticated attacker to exploit improper input validation, enabling code injection through the HTTP Discovery transport. This issue can be triggered if the activemq-http module is present on the classpath. Attackers can leverage this flaw by configuring a malicious HTTP endpoint to return a VM transport, circumventing previous security measures. This enables them to execute remote code on the broker's JVM via the brokerConfig parameter, posing significant risks of arbitrary code execution. Users are urged to upgrade to the specified versions to mitigate this risk.

Affected Version(s)

Apache ActiveMQ 0 < 5.19.6

Apache ActiveMQ 6.0.0 < 6.2.5

Apache ActiveMQ All 0 < 5.19.6

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fatih Ersinadim
gggggggga
.