S4E just found a medium-severity finding from leaked token-api key scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 4, 2026

CVE-2026-40466 Scanner

CVE-2026-40466 Scanner - Remote Code Execution (RCE) vulnerability in Apache ActiveMQ

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-40466
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia if the activemq-http module is on the classpath. A malicious HTTP endpoint can return a VM transport through the HTTP URI which will bypass the validation added in CVE-2026-34197. The attacker can then use the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ All: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 5.19.6 or 6.2.5, which fixes the issue.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Apache ActiveMQ Brokerby Apache Software Foundation
AFFECTED< 5.19.6SAFE ✓≥ 5.19.6
Apache ActiveMQ Allby Apache Software Foundation
AFFECTED< 5.19.6SAFE ✓≥ 5.19.6
Apache ActiveMQby Apache Software Foundation
AFFECTED< 5.19.6SAFE ✓≥ 5.19.6
Red Hat AMQ Broker 7by Red Hat
Updated Sep 9, 2026View on NVD →
Detail

Apache ActiveMQ is a message broker software that is widely used for sending messages between different components of an application. It is used by businesses globally to assist in integrating systems and applications with high reliability and availability. ActiveMQ is often implemented in environments where tasks such as real-time alerts, monitoring, or data transfer require quick and efficient message delivery. Companies in industries such as finance, e-commerce, transportation, and logistics rely on ActiveMQ for their enterprise-wide communication needs. Open-source by nature, it offers flexibility and is widely adopted in both small-scale and large-scale deployments. As a broker-based solution, it stands out for its ability to handle multiple languages and platforms, making it a popular choice for system architects and developers.

This vulnerability in Apache ActiveMQ allows an attacker to execute arbitrary code on the broker JVM, potentially leading to a full system compromise. The vulnerability arises from a flaw that allows a bypass of a previous security fix meant to block the "vm://" transport scheme. An attacker can exploit this by using the HTTP Discovery transport to execute code remotely when the activemq-http module is present. The attacker must have authenticated access to the Jolokia API. Such vulnerabilities are critical as they open up systems to unauthorized access, manipulation, or data theft.

Technically, the vulnerability is due to the oversight in the original security patch, which did not prevent the use of certain HTTP Discovery transport URIs. These URIs can return a transport URI that then loads a remote Spring XML application context. This leads to arbitrary code execution if used maliciously. The affected endpoint is the Jolokia API where authenticated requests can be sent, and the potential for exploitation is high, given the wide use of this module. The vulnerable parameter is the transport scheme that a malicious actor can manipulate. Notably, the vulnerability is contingent on having the activemq-http module on the classpath and authenticated access to Jolokia.

If exploited, this vulnerability can allow malicious actors to run arbitrary code on the server, leading to unauthorized access, data manipulation, or even full system compromise. The execution of arbitrary code could undermine the entire security posture of the affected environment. The exposure of sensitive data, unauthorized control over broker services, and potential disruptions in service availability are possible outcomes. Organizations could face severe reputational and financial damage if system integrity is breached.

REFERENCES

Solution Advice
  • Ensure that Apache ActiveMQ is updated to version 5.19.6 or later and 6.2.5 or later to mitigate the vulnerability.
  • Verify the configuration and ensure the activemq-http module is not on the classpath unless absolutely necessary.
  • Restrict access to the Jolokia API to trusted entities only, minimizing the risk of unauthorized exploitation.
  • Regularly audit and monitor usage logs to detect any unauthorized or suspicious activity related to network connectors.
  • Implement additional security measures by enforcing strong authentication and authorization for accessing sensitive API endpoints.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.