Vulnerability Remediation: CVE-2026-34197 in Automation Analytics and Intelligence (AAI)
search cancel

Vulnerability Remediation: CVE-2026-34197 in Automation Analytics and Intelligence (AAI)

book

Article ID: 445396

calendar_today

Updated On:

Products

Automation Analytics & Intelligence

Issue/Introduction

Security scans or vulnerability assessments identify vulnerable versions of Apache ActiveMQ libraries (e.g., activemq-all-5.16.7.jaractivemq-broker-5.16.7.jar, or activemq-6.1.6) within the AAI installation directory.

Environment

  • Product: Automation Analytics and Intelligence (AAI)
  • Versions: 24.4 and earlier
  • Vulnerability: CVE-2026-34197 (Apache ActiveMQ Remote Code Execution)

Cause

AAI 24.4 and earlier versions bundle versions of Apache ActiveMQ that are susceptible to CVE-2026-34197. This vulnerability allows an authenticated attacker to execute arbitrary code on the broker's JVM via improper input validation in the Jolokia JMX-HTTP bridge.

Resolution

This issue has been officially remediated by upgrading the bundled Apache ActiveMQ component to version 6.2.5.

Fix Version

  • AAI 24.4.1 (and later)

Implementation Details

Engineering addressed this remediation under defect DE187689. The following components were updated to include ActiveMQ 6.2.5 libraries:

  • aai.war
  • alert-service.war
  • subscription-service.war
  • activemq.war