Vulnerability record · CVE-2020-11998 · published 10 September 2020
CVE-2020-11998: Apache ActiveMQ JMX re-bind regression allows remote code execution
Apache · Activemq
A regression in the commit that prevents JMX re-binding causes RMIConnectorServer to receive an empty environment map instead of one containing authentication credentials. This leaves ActiveMQ's JMX endpoint without the intended authentication, allowing a remote client to create an MLet MBean and load MBeans from arbitrary URLs. The result is arbitrary code execution on the Java application hosting ActiveMQ.
Description
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade to Apache ActiveMQ 5.15.13
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and full code execution impact, plus a high EPSS percentile.
What it is
A regression in the commit that prevents JMX re-binding causes RMIConnectorServer to receive an empty environment map instead of one containing authentication credentials. This leaves ActiveMQ's JMX endpoint without the intended authentication, allowing a remote client to create an MLet MBean and load MBeans from arbitrary URLs. The result is arbitrary code execution on the Java application hosting ActiveMQ.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the ActiveMQ/Java process, leading to full compromise of confidentiality, integrity and availability.
Attack surface
Reachable over the network via the JMX/RMI connector with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description indicates the flaw is in how the connector server is initialized, so any exposed JMX listener is the entry point.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of exploitation activity. References are vendor advisories and Oracle patch notices only; no public exploit tag is present in the record.
What to do
- Upgrade to Apache ActiveMQ 5.15.13 or later as stated in the vendor advisory.
- Apply the relevant Oracle CPU patches for affected Oracle products that bundle ActiveMQ.
- Restrict network access to JMX/RMI ports so they are not reachable from untrusted networks.
- Enable JMX authentication and SSL, and run with a security manager where feasible.
- Audit for the regression in any locally maintained ActiveMQ builds and re-apply the JMX re-bind fix.
Detection
- Monitor JMX/RMI listener connections from unexpected remote hosts, especially to ActiveMQ broker ports.
- Alert on creation of javax.management.loading.MLet MBeans or MBean loading from remote URLs in JMX logs.
- Watch for outbound HTTP/URL fetches originating from the ActiveMQ Java process.
- Review process-level anomalies such as unexpected child processes or class loading from the broker JVM.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-11998 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11998), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.