CVE-2026-41044 Details
Description
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding that can be later used by a VM transport to load a remote Spring XML application. The attacker can then use the DestinationView mbean to send a message to trigger a VM transport creation that will reference this malicious broker name which can lead to loading the malicious Spring XML context file. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Broker: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ All: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.
A code injection vulnerability allowing remote code execution has been identified in Apache ActiveMQ, ActiveMQ Broker, and ActiveMQ All, affecting versions prior to 5.19.6 and 6.0.0 versions prior to 6.2.5. This vulnerability arises from improper input validation, which an authenticated attacker can exploit via the admin web console. By crafting a malicious broker name that bypasses validation, the attacker can inject an xbean binding. This binding can be used by a VM transport to load a remote Spring XML application. Once loaded, the Spring 'ResourceXmlApplicationContext' executes all singleton beans before the BrokerService has a chance to validate the configuration, leading to arbitrary code execution on the broker's JVM through methods like 'Runtime.exec()'.
Users are advised to upgrade to Apache ActiveMQ version 6.2.5 or 5.19.6, both of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-41044 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2461409 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41044.json | redhat-SADP | |
| http://www.openwall.com/lists/oss-security/2026/04/23/6 | CVE | Mailing ListThird Party Advisory |
| https://activemq.apache.org/security-advisories.data/CVE-2026-41044-announcement.txt | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | redhat-SADP |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache activemq | < 5.19.6 >= 6.0.0, < 6.2.5 |
CPE
Remediation
| |
| apache activemq broker | < 5.19.6 >= 6.0.0, < 6.2.5 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 24, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | New CVE Received | [email protected] |
| Apr 24, 2026 | CVE Modified | CVE |