Vulnerability record · CVE-2022-41678 · published 28 November 2023
CVE-2022-41678: Apache ActiveMQ Jolokia authenticated remote code execution
Apache · Activemq
An authenticated Jolokia user on Apache ActiveMQ can invoke JMX MBeans through the AgentServlet's POST handler, reaching ExecHandler#doHandleRequest via reflection. This enables arbitrary code execution, for example by abusing unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl on Java 11 and above to write a JSP webshell. The flaw is an authorization weakness in Jolokia's default configuration rather than a memory-safety bug.
Description
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able to create JmxRequest through JSONObject. And calls to org.jolokia.http.HttpRequestHandler#executeRequest. Into deeper calling stacks, org.jolokia.handler.ExecHandler#doHandleRequest can be invoked through refection. This could lead to RCE through via various mbeans. One example is unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl which exists on Java version above 11. 1 Call newRecording. 2 Call setConfiguration. And a webshell data hides in it. 3 Call startRecording. 4 Call copyTo method. The webshell will be written to a .jsp file. The mitigation is to restrict (by default) the actions authorized on Jolokia, or disable Jolokia. A more restrictive Jolokia configuration has been defined in default ActiveMQ distribution. We encourage users to upgrade to ActiveMQ distributions version including updated Jolokia configuration: 5.16.6, 5.17.4, 5.18.0, 6.0.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS (0.8581) make this a serious RCE risk, though it requires authenticated Jolokia access and is not in KEV.
What it is
An authenticated Jolokia user on Apache ActiveMQ can invoke JMX MBeans through the AgentServlet's POST handler, reaching ExecHandler#doHandleRequest via reflection. This enables arbitrary code execution, for example by abusing unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl on Java 11 and above to write a JSP webshell. The flaw is an authorization weakness in Jolokia's default configuration rather than a memory-safety bug.
Impact
An attacker with valid Jolokia credentials gains remote code execution on the ActiveMQ host, allowing webshell deployment and full compromise of the broker and its data.
Attack surface
Reachable over the network through the Jolokia HTTP endpoint exposed by ActiveMQ's Jetty configuration, specifically POST requests to /api/jolokia. Authentication is required (PR:L) but no user interaction is needed, and the attack is network-accessible with low complexity.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high at 0.8581 (99.7th percentile), indicating strong likelihood of exploitation activity. Vendor advisories confirm the issue and the fix.
What to do
- Upgrade to ActiveMQ 5.16.6, 5.17.4, 5.18.0, or 6.0.0, which ship a more restrictive Jolokia configuration.
- If upgrade is not possible, restrict the actions Jolokia authorizes by default or disable the Jolokia agent entirely.
- Restrict network access to the Jolokia endpoint so only trusted management hosts can reach it.
- Rotate credentials for any account with Jolokia access and audit for unauthorized MBean invocations.
- Run ActiveMQ on a Java version where the FlightRecorderMXBean deserialization path is not exposed, or block that MBean from Jolokia exec.
Detection
- Monitor Jolokia POST requests to /api/jolokia for exec operations against MBeans such as FlightRecorderMXBeanImpl.
- Alert on creation of new .jsp files in ActiveMQ web directories or other unexpected file writes.
- Review ActiveMQ and Jolokia logs for anomalous JMX exec calls, especially newRecording, setConfiguration, startRecording, and copyTo sequences.
- Baseline and monitor outbound connections from the ActiveMQ host for signs of post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-41678 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41678), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.