← Vulnerability feed

Vulnerability record · CVE-2020-11998 · published 10 September 2020

CVE-2020-11998: Apache ActiveMQ JMX re-bind regression allows remote code execution

Apache · Activemq

A regression in the commit that prevents JMX re-binding causes RMIConnectorServer to receive an empty environment map instead of one containing authentication credentials. This leaves ActiveMQ's JMX endpoint without the intended authentication, allowing a remote client to create an MLet MBean and load MBeans from arbitrary URLs. The result is arbitrary code execution on the Java application hosting ActiveMQ.

9.8 CVSS 3.1 Critical EPSS 51% · top 1.1%
9.8CVSS 3.1 base score, v2 7.5
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade to Apache ActiveMQ 5.15.13

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and full code execution impact, plus a high EPSS percentile.

What it is

A regression in the commit that prevents JMX re-binding causes RMIConnectorServer to receive an empty environment map instead of one containing authentication credentials. This leaves ActiveMQ's JMX endpoint without the intended authentication, allowing a remote client to create an MLet MBean and load MBeans from arbitrary URLs. The result is arbitrary code execution on the Java application hosting ActiveMQ.

Impact

An unauthenticated remote attacker can execute arbitrary code in the context of the ActiveMQ/Java process, leading to full compromise of confidentiality, integrity and availability.

Attack surface

Reachable over the network via the JMX/RMI connector with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description indicates the flaw is in how the connector server is initialized, so any exposed JMX listener is the entry point.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of exploitation activity. References are vendor advisories and Oracle patch notices only; no public exploit tag is present in the record.

What to do

  • Upgrade to Apache ActiveMQ 5.15.13 or later as stated in the vendor advisory.
  • Apply the relevant Oracle CPU patches for affected Oracle products that bundle ActiveMQ.
  • Restrict network access to JMX/RMI ports so they are not reachable from untrusted networks.
  • Enable JMX authentication and SSL, and run with a security manager where feasible.
  • Audit for the regression in any locally maintained ActiveMQ builds and re-apply the JMX re-bind fix.

Detection

  • Monitor JMX/RMI listener connections from unexpected remote hosts, especially to ActiveMQ broker ports.
  • Alert on creation of javax.management.loading.MLet MBeans or MBean loading from remote URLs in JMX logs.
  • Watch for outbound HTTP/URL fetches originating from the ActiveMQ Java process.
  • Review process-level anomalies such as unexpected child processes or class loading from the broker JVM.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11998 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed9.8CVE-2017-9841PHPUnit eval-stdin.php remote PHP code executionPHPUnit before 4.8.28 and 5.x before 5.6.3 ships Util/PHP/eval-stdin.php, which evaluates HTTP POST body content as PHP when it begins with a "<?php …KEVEPSS 100%analysed9.8CVE-2016-3088Apache ActiveMQ Fileserver unrestricted file upload to RCEThe Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 accepts HTTP PUT uploads and HTTP MOVE requests without adequate validation, lett…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed7.8CVE-2019-0211Apache HTTP Server scoreboard use-after-free local privilege escalationApache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-p…KEVEPSS 65%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed

Source: NIST National Vulnerability Database (record CVE-2020-11998), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.