Detects Apache ActiveMQ Classic instances before 5.19.4 / 6.2.3 where the Jolokia JMX-HTTP bridge is accessible with default credentials (admin:admin). The addNetworkConnector MBean operation accepts crafted vm:// URIs with brokerConfig parameters that load remote Spring XML application contexts, enabling arbitrary code execution. This bug has existed for 13+ years.
Is your app exploitable through CVE-2026-34197?
Scan your domain free