Hitachi Energy SOI exposed to ActiveMQ RCE flaw (CVE-2026-34197)

Hitachi Energy SOI exposed to ActiveMQ RCE flaw (CVE-2026-34197)

At a glance

Severity CRITICAL
CVSS CVE-2026-34197: 8.8
EPSS (30-day exploit probability) CVE-2026-34197: 15.5%
In CISA KEV (exploited) Yes, due 2026-04-30
Vendor Apache
CVE IDs CVE-2026-34197

A Hitachi Energy SOI vulnerability affects versions 2.0.0 to 2.2.0 because the product bundles an Apache ActiveMQ message broker with a code-execution flaw, CVE-2026-34197. The ActiveMQ bug is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, with a federal due date of 2026-04-30, and CISA published an ICS advisory (ICSA-26-279-04) for the Hitachi Energy product on October 6, 2026.

What happened

CISA’s advisory says Hitachi Energy is aware of a remote code execution vulnerability in the Apache ActiveMQ component of SOI. The vendor reported it to CISA through its internal team. The upstream flaw is in ActiveMQ Classic, whose web console exposes the Jolokia JMX-HTTP bridge at /api/jolokia/. The default Jolokia policy allows exec operations on all ActiveMQ management beans.

An authenticated attacker can call those operations with a crafted discovery URI. That makes the broker load a remote Spring XML application context, which runs attacker-chosen code on the broker’s JVM.

Am I affected? Hitachi Energy SOI versions

  • Hitachi Energy SOI 2.0.0 to 2.2.0: known affected, per the CISA advisory.
  • Apache ActiveMQ (NVD): versions before 5.19.4, and 6.0.0 before 6.2.3. Fixed in 5.19.4 and 6.2.3.

The advisory lists the sector as energy, deployed worldwide, with Hitachi Energy headquartered in Switzerland. Whether other products that embed ActiveMQ are affected is not disclosed in these sources.

Technical details

The weakness sits in how ActiveMQ validates the discovery URI handed to its broker management operations. Because the Spring context is built before the broker validates its configuration, the code runs even if the configuration is later rejected.

  • CVSS 3.1 base score: 8.8 (High), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. That means network reachable, low complexity, low privileges, no user interaction.
  • Weaknesses: CWE-20 (improper input validation), CWE-78 (OS command injection) and CWE-94 (code injection).
  • KEV: added 2026-04-16 as Apache ActiveMQ Improper Input Validation Vulnerability. Use in ransomware campaigns is listed as unknown.
  • EPSS (probability of exploitation in the next 30 days): 0.15492, about 15%.
  • The attacker needs credentials. The sources do not say how easily they could be obtained in an SOI deployment.

Why this matters

Analysis, not new facts. The flaw is known to be exploited against ActiveMQ and the code runs on the message broker, a component that often sits between plant, operations and enterprise systems. In an energy environment, a compromised broker can become a pivot point. The low privilege requirement means any stolen or default console account may be enough, so treat the ActiveMQ web console as high-risk wherever it is reachable.

Detection and hunting ideas

Hitachi Energy and CISA do not report any observed attacks against SOI itself in this advisory, so hunting is about confirming nothing unexpected happened before you patch.

No indicators of compromise are published. Based on the mechanism, defenders can look for:

  • Requests to /api/jolokia/ on the ActiveMQ web console, especially from unexpected hosts.
  • Broker logs showing new network connectors or transport connectors that you did not configure.
  • Outbound connections from the broker host to fetch remote XML configuration.
  • The ActiveMQ JVM spawning shells or other child processes.

What to do: fix Hitachi Energy SOI CVE-2026-34197

  1. Apply the vendor patch SOI EP2. It upgrades the SOI Core ActiveMQ to 5.19.5, installs OpenJDK 11 for the broker, upgrades the management scripts and the ActiveMQ client libraries in the WildFly module. EP2 is cumulative and covers EP1.
  2. Because the flaw is in CISA KEV, treat this as a patch-within-hours item for exposed systems rather than the next maintenance window.
  3. Until patched, follow Hitachi Energy’s general mitigation factors and product deployment guidelines. Restrict network access to the ActiveMQ web console and review which accounts can log in.
  4. Run the hunting checks above on any SOI broker that was reachable before patching.
  5. If you run standalone ActiveMQ, upgrade to 5.19.4 or 6.2.3 or later.

Sources

Spotted an error or outdated detail? Email contact@cyberstrikenews.com with the article link. We correct and note every change. Read our Editorial Policy.

Similar Posts