← Vulnerability feed

Vulnerability record · CVE-2022-41678 · published 28 November 2023

CVE-2022-41678: Apache ActiveMQ Jolokia authenticated remote code execution

Apache · Activemq

An authenticated Jolokia user on Apache ActiveMQ can invoke JMX MBeans through the AgentServlet's POST handler, reaching ExecHandler#doHandleRequest via reflection. This enables arbitrary code execution, for example by abusing unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl on Java 11 and above to write a JSP webshell. The flaw is an authorization weakness in Jolokia's default configuration rather than a memory-safety bug.

8.8 CVSS 3.1 High EPSS 86% · top 0.3% CWE-287 · Improper authentication
8.8CVSS 3.1 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able to create JmxRequest through JSONObject. And calls to org.jolokia.http.HttpRequestHandler#executeRequest. Into deeper calling stacks, org.jolokia.handler.ExecHandler#doHandleRequest can be invoked through refection. This could lead to RCE through via various mbeans. One example is unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl which exists on Java version above 11. 1 Call newRecording. 2 Call setConfiguration. And a webshell data hides in it. 3 Call startRecording. 4 Call copyTo method. The webshell will be written to a .jsp file. The mitigation is to restrict (by default) the actions authorized on Jolokia, or disable Jolokia. A more restrictive Jolokia configuration has been defined in default ActiveMQ distribution. We encourage users to upgrade to ActiveMQ distributions version including updated Jolokia configuration: 5.16.6, 5.17.4, 5.18.0, 6.0.0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with network reachability and high EPSS (0.8581) make this a serious RCE risk, though it requires authenticated Jolokia access and is not in KEV.

What it is

An authenticated Jolokia user on Apache ActiveMQ can invoke JMX MBeans through the AgentServlet's POST handler, reaching ExecHandler#doHandleRequest via reflection. This enables arbitrary code execution, for example by abusing unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl on Java 11 and above to write a JSP webshell. The flaw is an authorization weakness in Jolokia's default configuration rather than a memory-safety bug.

Impact

An attacker with valid Jolokia credentials gains remote code execution on the ActiveMQ host, allowing webshell deployment and full compromise of the broker and its data.

Attack surface

Reachable over the network through the Jolokia HTTP endpoint exposed by ActiveMQ's Jetty configuration, specifically POST requests to /api/jolokia. Authentication is required (PR:L) but no user interaction is needed, and the attack is network-accessible with low complexity.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high at 0.8581 (99.7th percentile), indicating strong likelihood of exploitation activity. Vendor advisories confirm the issue and the fix.

What to do

  • Upgrade to ActiveMQ 5.16.6, 5.17.4, 5.18.0, or 6.0.0, which ship a more restrictive Jolokia configuration.
  • If upgrade is not possible, restrict the actions Jolokia authorizes by default or disable the Jolokia agent entirely.
  • Restrict network access to the Jolokia endpoint so only trusted management hosts can reach it.
  • Rotate credentials for any account with Jolokia access and audit for unauthorized MBean invocations.
  • Run ActiveMQ on a Java version where the FlightRecorderMXBean deserialization path is not exposed, or block that MBean from Jolokia exec.

Detection

  • Monitor Jolokia POST requests to /api/jolokia for exec operations against MBeans such as FlightRecorderMXBeanImpl.
  • Alert on creation of new .jsp files in ActiveMQ web directories or other unexpected file writes.
  • Review ActiveMQ and Jolokia logs for anomalous JMX exec calls, especially newRecording, setConfiguration, startRecording, and copyTo sequences.
  • Baseline and monitor outbound connections from the ActiveMQ host for signs of post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-41678 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed9.8CVE-2016-3088Apache ActiveMQ Fileserver unrestricted file upload to RCEThe Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 accepts HTTP PUT uploads and HTTP MOVE requests without adequate validation, lett…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed9.9CVE-2021-21345XStream deserialization allows remote command executionXStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, allowing code injection and OS command execution. The flaw is a …EPSS 72%analysed9.8CVE-2021-21347Netapp oncommand insight unrestricted file upload vulnerabilityXStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…EPSS 14%9.8CVE-2021-21350Netapp oncommand insight unrestricted file upload vulnerabilityXStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…EPSS 15%9.8CVE-2021-21344XStream deserialization allows remote code executionXStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, letting a remote attacker craft a stream that loads and executes…EPSS 76%analysed9.8CVE-2021-21346XStream deserialization allows remote code executionXStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, letting a remote attacker load and execute arbitrary code by man…EPSS 76%analysed

Source: NIST National Vulnerability Database (record CVE-2022-41678), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.