Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-84218— Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix)

Quick assessment

Affected
Red Hat Red Hat build of Apache Camel 4 for Quarkus 3
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Jolokia 的 JSR-160 代理功能中存在一个缺陷:由于对客户端可控的 JMX 服务 URL 验证不足,导致用于缓解 CVE-2018-1000130 的黑名单机制可被绕过。该代理从 Jolokia 的 POST 请求中获取 值,并将其传递给 和 以建立远程 JMX 连接。现有的黑名单仅拒绝匹配 的 URL,攻击者可以使用其他有效的 JMX 服务 URL 形式来绕过,例如使用 协议或带有非空 JMX 主机分量的 LDAP URL。这些 URL 会被接受为有效的 对象,并可能导致 Jolokia agent

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-84218

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix)
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不完整的黑名单
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat build of Apache Camel 4 for Quarkus 3 - cpe:/a:redhat:camel_quarkus:3
Red Hat Red Hat build of Apache Camel for Spring Boot 4 - cpe:/a:redhat:camel_spring_boot:4
Red Hat Red Hat Fuse 7 - cpe:/a:redhat:jboss_fuse:7
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6

II. Public POCs for CVE-2026-84218

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-84218

登录查看更多情报信息。

Vendor Advisories for CVE-2026-84218 (1)

Other References for CVE-2026-84218 (1)

Other References for CVE-2026-84218 (1)

Same Patch Batch · Red Hat · 2026-09-01 · 3 CVEs total

CVE-2026-11873 6.5 MEDIUM Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java
CVE-2026-53682 5.3 MEDIUM Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts

IV. Related Vulnerabilities

V. Comments for CVE-2026-84218

No comments yet


Leave a comment