PatchSiren cyber security CVE debrief
CVE-2026-84218 Red Hat CVE debrief
A flaw in Jolokia's JSR-160 proxy functionality allows insufficient validation of client-controlled JMX service URLs, bypassing the denylist introduced to mitigate CVE-2018-1000130. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.
- Vendor
- Red Hat
- Product
- org.jolokia:jolokia-service-jsr160
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-01
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-09-01
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Jolokia deployments, particularly those using JSR-160 proxy functionality, should assess exposure and prioritize verification and remediation. Affected deployments should verify and update Jolokia versions, restrict access to JMX services, and monitor for suspicious activity. Defenders should care about CVE-2026-84218 because it allows an attacker to bypass the denylist in Jolokia's JSR-160 proxy functionality, potentially leading
Why it matters
Defenders should care about CVE-2026-84218 because it allows an attacker to bypass the denylist in Jolokia's JSR-160 proxy functionality, potentially leading to SSRF, credential forwarding, and remote code execution. Affected deployments should verify and update Jolokia versions, restrict access to JMX services, and monitor for suspicious activity.
- Potential for server-side request forgery (SSRF)
- Possible forwarding of supplied JMX credentials to remote endpoints
- Potential for remote code execution depending on target JVM configuration
Technical summary
The Jolokia JSR-160 proxy functionality does not properly validate client-controlled JMX service URLs, allowing a bypass of the denylist and potentially leading to SSRF, JMX credential forwarding, and remote code execution. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM. Affected deployments should verify and update Jolokia versions to 2.6.2 or later, restrict access to JMX services, and monitor for suspicious JNDI lookups.
Defensive priority
Defenders should prioritize verifying and updating Jolokia versions to 2.6.2 or later, restricting access to JMX services, and monitoring for suspicious JNDI lookups.
Recommended defensive actions
- Verify and update Jolokia to version 2.6.2 or later
- Restrict access to JMX services
- Monitor for suspicious JNDI lookups
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The source corpus provides details on the vulnerability, including the insufficient validation of client-controlled JMX service URLs and the potential for SSRF and remote code execution. Affected deployments should verify and update Jolokia versions, restrict access to JMX services, and monitor for suspicious activity. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX
Sources and references
Verified primary and authoritative sources
-
CVE-2026-84218 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-84218
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-84218 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84218
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
jolokia-service-jsr160 Incomplete target JMX Service URL deny list handling for user-controlled
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Maven/GHSA-c9ff-59g8-m36q.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/jolokia/jolokia/issues/1049
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-84218
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/advisories/GHSA-c9ff-59g8-m36q
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/jolokia/jolokia
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://jolokia.org/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.