PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84218 Red Hat CVE debrief

A flaw in Jolokia's JSR-160 proxy functionality allows insufficient validation of client-controlled JMX service URLs, bypassing the denylist introduced to mitigate CVE-2018-1000130. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.

Vendor
Red Hat
Product
org.jolokia:jolokia-service-jsr160
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-01
Original CVE updated
2026-10-07
Advisory published
2026-09-01
Advisory updated
2026-10-07

Who should care

Defenders responsible for Jolokia deployments, particularly those using JSR-160 proxy functionality, should assess exposure and prioritize verification and remediation. Affected deployments should verify and update Jolokia versions, restrict access to JMX services, and monitor for suspicious activity. Defenders should care about CVE-2026-84218 because it allows an attacker to bypass the denylist in Jolokia's JSR-160 proxy functionality, potentially leading

Why it matters

Defenders should care about CVE-2026-84218 because it allows an attacker to bypass the denylist in Jolokia's JSR-160 proxy functionality, potentially leading to SSRF, credential forwarding, and remote code execution. Affected deployments should verify and update Jolokia versions, restrict access to JMX services, and monitor for suspicious activity.

  • Potential for server-side request forgery (SSRF)
  • Possible forwarding of supplied JMX credentials to remote endpoints
  • Potential for remote code execution depending on target JVM configuration

Technical summary

The Jolokia JSR-160 proxy functionality does not properly validate client-controlled JMX service URLs, allowing a bypass of the denylist and potentially leading to SSRF, JMX credential forwarding, and remote code execution. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM. Affected deployments should verify and update Jolokia versions to 2.6.2 or later, restrict access to JMX services, and monitor for suspicious JNDI lookups.

Defensive priority

Defenders should prioritize verifying and updating Jolokia versions to 2.6.2 or later, restricting access to JMX services, and monitoring for suspicious JNDI lookups.

Recommended defensive actions

  • Verify and update Jolokia to version 2.6.2 or later
  • Restrict access to JMX services
  • Monitor for suspicious JNDI lookups
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The source corpus provides details on the vulnerability, including the insufficient validation of client-controlled JMX service URLs and the potential for SSRF and remote code execution. Affected deployments should verify and update Jolokia versions, restrict access to JMX services, and monitor for suspicious activity. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84218 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84218

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84218 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84218

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.