Actively Exploited Apache ActiveMQ Flaw Puts Hitachi Energy SOI Systems at Risk
Hitachi Energy has published an advisory confirming that its SOI product is affected by a remote code execution vulnerability inherited from the Apache ActiveMQ message broker bundled with the platform. The flaw, tracked as CVE-2026-34197, is classed as improper input validation combined with improper control of generation of code, better known as code injection (CWE-94). It carries a CVSS v3.1 base score of 8.8 with the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, meaning it is reachable over the network, needs only low-level credentials and no user interaction, and fully compromises confidentiality, integrity and availability. SOI versions 2.0.0 through 2.2.0 inclusive are listed as known affected. SOI is deployed worldwide in the energy sector, and the vendor's own internal team reported the issue to CISA.
The mechanism is well documented in the advisory. Apache ActiveMQ Classic exposes a Jolokia JMX-to-HTTP bridge at the path /api/jolokia/ on its web console, and the default Jolokia access policy permits exec operations against every ActiveMQ MBean under org.apache.activemq:*. That set includes BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String), both of which accept a connector URI. An authenticated attacker can call one of these operations with a crafted discovery URI that drives the VM transport's brokerConfig parameter into loading a remote Spring XML application context through ResourceXmlApplicationContext. Because Spring instantiates all singleton beans before the BrokerService ever validates the supplied configuration, a hostile XML document can reach bean factory methods such as Runtime.exec() and execute arbitrary code inside the broker's JVM. The attacker therefore converts a management interface call into full command execution on the host running the broker.
The risk here is sharpened considerably by what is already happening in the wild. CVE-2026-34197 is listed in the CISA Known Exploited Vulnerabilities catalog, added on 16 April 2026, which means exploitation has been confirmed rather than merely predicted, and FIRST EPSS currently places the probability of exploitation activity in the next 30 days at 15.5 percent. The barrier to entry is low: the attacker needs valid but unprivileged credentials, and from there the exploitation path uses documented ActiveMQ management functionality rather than memory corruption or any fragile technique, so reliability is high and tooling is easy to reproduce. SOI sits inside process control environments in the energy sector, where a broker compromise does not stay contained to one service — the JMS broker is the messaging spine between SOI components, so code execution on it offers a view of operational message traffic, the ability to tamper with or inject messages, and a pivot point into adjacent control network hosts. Any deployment where the ActiveMQ web console or the Jolokia endpoint is reachable from a business network, a remote access concentrator or, worst case, the internet, should be treated as directly exposed. The vendor has released a cumulative patch, SOI EP2, which replaces the bundled ActiveMQ with version 5.19.5, refreshes the SOI management scripts, installs an upgraded OpenJDK 11 runtime for the broker and updates the ActiveMQ client libraries inside the WildFly module; EP2 supersedes the earlier EP1 patch. Until that patch is in place, the exposure is live, confirmed exploited elsewhere, and sitting in critical infrastructure.
Attack Surface
Web Application, System Management Service, Infrastructure
Tactics
Initial Access, Execution, Impact
Techniques
- T1190 – Exploit Public-Facing Application
- T1059 – Command and Scripting Interpreter
- T1203 – Exploitation for Client Execution
SuperPRO's Threat Countermeasures Procedures
- Apply the Hitachi Energy SOI EP2 cumulative patch to all SOI installations in the 2.0.0 to 2.2.0 range. EP2 upgrades the bundled ActiveMQ JMS broker to version 5.19.5, supersedes the earlier EP1 patch, updates the SOI management scripts, installs an upgraded OpenJDK 11 runtime for the broker and refreshes the ActiveMQ client libraries in the WildFly module.
- Block external and business-network access to the ActiveMQ web console and specifically to the Jolokia bridge path /api/jolokia/, restricting it to a named administrative subnet or jump host at the firewall until EP2 is deployed.
- Harden the Jolokia access policy on any ActiveMQ instance that cannot be patched immediately by denying exec operations on the org.apache.activemq:* MBean namespace, in particular BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).
- Create detection for HTTP POST requests to /api/jolokia/ whose body contains the strings addNetworkConnector, addConnector or brokerConfig, and alert on any outbound HTTP fetch by the broker JVM for a remote Spring XML application context.
- Alert on child processes spawned by the ActiveMQ broker JVM — cmd.exe, powershell.exe, /bin/sh or curl under the broker process tree indicates Runtime.exec() abuse through the ResourceXmlApplicationContext bean instantiation path.
- Audit and rotate ActiveMQ web console and broker accounts, removing default or shared logins, since CVE-2026-34197 requires only low-privilege authenticated access (PR:L) to reach the vulnerable management operations.
- Place SOI and its process control network behind a firewall with a minimal exposed port set, remove any direct internet path, and require VPN or equivalent hardened remote access for engineering sessions, in line with the Hitachi Energy deployment guidelines referenced in the advisory.