CVE-2026-49434
Apache ActiveMQ Classic vulnerability analysis and mitigation

Overview

CVE-2026-49434 is an Improper Input Validation vulnerability in Apache ActiveMQ's LdapNetworkConnector component, allowing an attacker with LDAP write access to instantiate denied transports inside the broker JVM and spawn a second BrokerService. It affects Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All versions before 5.19.8 and from 6.0.0 before 6.2.7. The vulnerability was disclosed on June 29, 2026, via the Apache security mailing list and the oss-security list. It carries a CVSS v3.1 base score of 7.5 (High) (Apache Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-20 (Improper Input Validation) and CWE-90 (LDAP Injection). When Apache ActiveMQ is configured to use LdapNetworkConnector, it queries an LDAP directory using a configured searchBase and searchFilter to discover broker connectors. An attacker with write access to matching LDAP entries can inject malicious transport URIs that bypass the broker's transport deny-list, causing the broker JVM to instantiate unauthorized transports and fetch attacker-controlled URLs, ultimately spawning a second BrokerService within the same JVM process. Exploitation requires the attacker to have LDAP write privileges on entries matching the broker's search configuration — this is a non-trivial precondition that limits the attack surface (oss-security, Red Hat Bugzilla).

Impact

Successful exploitation allows an attacker to instantiate unauthorized transports and spawn an arbitrary BrokerService inside the broker JVM, enabling potential remote code execution within the broker process. The primary impact is on integrity (CVSS integrity impact: High), as the attacker can manipulate broker behavior and cause it to fetch and process attacker-controlled content. Confidentiality and availability are not directly impacted per the CVSS scoring, but the ability to execute code within the broker JVM could be leveraged for lateral movement or data exfiltration in a broader attack chain (GitHub Advisory, Red Hat Bugzilla).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Apache Advisory). The EPSS score is approximately 0.659%, placing it in the 47th percentile for exploitation likelihood within 30 days (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" at this time, though the attack is rated as automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires LDAP write access, which significantly raises the bar for unauthenticated remote attackers.

Exploitation steps

  1. Reconnaissance: Identify Apache ActiveMQ deployments configured with LdapNetworkConnector, which requires the broker's activemq.xml to reference an LDAP server with a defined searchBase and searchFilter.
  2. Gain LDAP Write Access: Obtain credentials or exploit a misconfiguration to gain write access to LDAP entries that match the broker's configured searchBase and searchFilter (e.g., through credential theft, LDAP misconfiguration, or a compromised LDAP account).
  3. Inject Malicious Transport URI: Modify or create an LDAP entry within the search scope to include a malicious transport URI (e.g., a custom or otherwise denied transport scheme pointing to an attacker-controlled server).
  4. Trigger Broker LDAP Query: Wait for or trigger the ActiveMQ broker to re-query the LDAP directory (e.g., on broker restart or connector refresh), causing it to read the malicious entry.
  5. Instantiate Denied Transport: The broker processes the attacker-supplied URI without proper validation, instantiating the denied transport and fetching the attacker-controlled URL.
  6. Spawn Second BrokerService: The fetched content causes a second BrokerService to be spawned within the same JVM, enabling arbitrary code execution in the broker process context (oss-security, Red Hat Bugzilla).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS connections from the ActiveMQ broker process to unknown or external URLs; unusual LDAP query traffic from the broker to the LDAP server with modified search results.
  • Logs: ActiveMQ broker logs showing instantiation of unexpected or denied transport URIs; log entries referencing a second BrokerService starting within the same JVM; errors or warnings from LdapNetworkConnector processing unexpected entries.
  • Process: Unexpected child processes or network connections spawned by the ActiveMQ JVM process; a second BrokerService instance appearing in JVM thread dumps or heap analysis.
  • LDAP Directory: New or modified LDAP entries within the broker's configured searchBase containing unusual transport URI attributes not created by administrators.

Mitigation and workarounds

Apache has released fixed versions 5.19.8 and 6.2.7, which address this vulnerability; upgrading to one of these versions is the recommended remediation (Apache Advisory). As a workaround, restrict LDAP write access to trusted administrators only, ensuring no unauthorized users can modify entries matching the broker's searchBase and searchFilter. Additionally, review and tighten the LDAP searchBase and searchFilter configurations to minimize the scope of entries the broker will process. Monitor the LDAP directory for unauthorized modifications to entries within the broker's search scope.

Community reactions

The vulnerability was reported to the oss-security mailing list on June 29, 2026, by Christopher L. Shannon of the Apache ActiveMQ project, who rated it as "moderate" severity despite the CVSS High score (oss-security). Red Hat opened a tracking bug (Bug 2494843) and assigned it high priority/severity, with 56 users CC'd, indicating broad interest across the Red Hat product portfolio (Red Hat Bugzilla). Security news outlet SecurityOnline.info covered the vulnerability as part of a broader Apache ActiveMQ advisory roundup. Community reaction has been measured, consistent with the non-trivial exploitation preconditions (LDAP write access required).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

activemq

Affected

sid

activemq

Affected

trixie

activemq

Affected

Ubuntu

Unknown

bionic (esm-apps)

activemq

Unknown

devel

activemq

Unknown

focal (esm-apps)

activemq

Unknown

jammy

activemq

Unknown

jammy (esm-apps)

activemq

Unknown

noble

activemq

Unknown

noble (esm-apps)

activemq

Unknown

resolute

activemq

Unknown

RHEL / CentOS

Affected

RHEL 8

log4j:2/log4j.src

Affected

SourceThis report was generated using AI

Related Apache ActiveMQ Classic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59878HIGH7.5
  • Apache ActiveMQ Classic logoApache ActiveMQ Classic
  • apache-activemq-5.19
NoYesJul 28, 2026
CVE-2026-54475HIGH7.5
  • Apache ActiveMQ Classic logoApache ActiveMQ Classic
  • activemq
NoYesJun 30, 2026
CVE-2026-53917HIGH7.5
  • Apache ActiveMQ Classic logoApache ActiveMQ Classic
  • log4j:2::log4j
NoYesJun 30, 2026
CVE-2026-53916HIGH7.5
  • Apache ActiveMQ Classic logoApache ActiveMQ Classic
  • log4j-web
NoYesJun 30, 2026
CVE-2026-61487MEDIUM6.5
  • Apache ActiveMQ Classic logoApache ActiveMQ Classic
  • apache-activemq-5.19
NoYesJul 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management