
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-49434 is an Improper Input Validation vulnerability in Apache ActiveMQ's LdapNetworkConnector component, allowing an attacker with LDAP write access to instantiate denied transports inside the broker JVM and spawn a second BrokerService. It affects Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All versions before 5.19.8 and from 6.0.0 before 6.2.7. The vulnerability was disclosed on June 29, 2026, via the Apache security mailing list and the oss-security list. It carries a CVSS v3.1 base score of 7.5 (High) (Apache Advisory, GitHub Advisory).
The root cause is classified as CWE-20 (Improper Input Validation) and CWE-90 (LDAP Injection). When Apache ActiveMQ is configured to use LdapNetworkConnector, it queries an LDAP directory using a configured searchBase and searchFilter to discover broker connectors. An attacker with write access to matching LDAP entries can inject malicious transport URIs that bypass the broker's transport deny-list, causing the broker JVM to instantiate unauthorized transports and fetch attacker-controlled URLs, ultimately spawning a second BrokerService within the same JVM process. Exploitation requires the attacker to have LDAP write privileges on entries matching the broker's search configuration — this is a non-trivial precondition that limits the attack surface (oss-security, Red Hat Bugzilla).
Successful exploitation allows an attacker to instantiate unauthorized transports and spawn an arbitrary BrokerService inside the broker JVM, enabling potential remote code execution within the broker process. The primary impact is on integrity (CVSS integrity impact: High), as the attacker can manipulate broker behavior and cause it to fetch and process attacker-controlled content. Confidentiality and availability are not directly impacted per the CVSS scoring, but the ability to execute code within the broker JVM could be leveraged for lateral movement or data exfiltration in a broader attack chain (GitHub Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Apache Advisory). The EPSS score is approximately 0.659%, placing it in the 47th percentile for exploitation likelihood within 30 days (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" at this time, though the attack is rated as automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires LDAP write access, which significantly raises the bar for unauthenticated remote attackers.
LdapNetworkConnector, which requires the broker's activemq.xml to reference an LDAP server with a defined searchBase and searchFilter.searchBase and searchFilter (e.g., through credential theft, LDAP misconfiguration, or a compromised LDAP account).BrokerService to be spawned within the same JVM, enabling arbitrary code execution in the broker process context (oss-security, Red Hat Bugzilla).BrokerService starting within the same JVM; errors or warnings from LdapNetworkConnector processing unexpected entries.BrokerService instance appearing in JVM thread dumps or heap analysis.searchBase containing unusual transport URI attributes not created by administrators.Apache has released fixed versions 5.19.8 and 6.2.7, which address this vulnerability; upgrading to one of these versions is the recommended remediation (Apache Advisory). As a workaround, restrict LDAP write access to trusted administrators only, ensuring no unauthorized users can modify entries matching the broker's searchBase and searchFilter. Additionally, review and tighten the LDAP searchBase and searchFilter configurations to minimize the scope of entries the broker will process. Monitor the LDAP directory for unauthorized modifications to entries within the broker's search scope.
The vulnerability was reported to the oss-security mailing list on June 29, 2026, by Christopher L. Shannon of the Apache ActiveMQ project, who rated it as "moderate" severity despite the CVSS High score (oss-security). Red Hat opened a tracking bug (Bug 2494843) and assigned it high priority/severity, with 56 users CC'd, indicating broad interest across the Red Hat product portfolio (Red Hat Bugzilla). Security news outlet SecurityOnline.info covered the vulnerability as part of a broader Apache ActiveMQ advisory roundup. Community reaction has been measured, consistent with the non-trivial exploitation preconditions (LDAP write access required).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
activemq
devel
activemq
focal (esm-apps)
activemq
jammy
activemq
jammy (esm-apps)
activemq
noble
activemq
noble (esm-apps)
activemq
resolute
activemq
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."