{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/jolokia/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jolokia:jolokia:*:*:*:*:*:*:*:*","cpe:2.3:a:jolokia:webarchive_agent:1.3.7:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-84218"},{"cvss":8.1,"id":"CVE-2018-1000130"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Jolokia"],"_cs_severities":["high"],"_cs_tags":["vulnerability","java","jmx","jndi","ssrf"],"_cs_type":"advisory","_cs_vendors":["Jolokia"],"content_html":"\u003cp\u003eCVE-2026-84218 describes a security vulnerability in the Jolokia JSR-160 proxy functionality. The flaw stems from insufficient validation of client-controlled JMX service URLs, which effectively bypasses the security denylist originally established to address CVE-2018-1000130. By sending a crafted Jolokia POST request, an attacker can manipulate the \u003ccode\u003etarget.url\u003c/code\u003e parameter. Because the existing denylist logic only explicitly rejects standard \u003ccode\u003eservice:jmx:rmi:///jndi/ldap:.*\u003c/code\u003e patterns, it fails to account for alternative valid JMX service URL formats, such as \u003ccode\u003eldaps://\u003c/code\u003e schemes or LDAP URLs containing a non-empty JMX host component.\u003c/p\u003e\n\u003cp\u003eWhen processed, these malformed URLs are accepted as valid \u003ccode\u003eJMXServiceURL\u003c/code\u003e objects, prompting the Jolokia agent JVM to perform an unintended JNDI lookup against an attacker-controlled endpoint. The impact of this behavior ranges from server-side request forgery (SSRF) and the exfiltration of JMX credentials to potential remote code execution (RCE), depending on the specific classes available within the target JVM classpath. This vulnerability is highly relevant for environments deploying Jolokia as an agent for JMX management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform SSRF and credential exfiltration via the Jolokia agent. Depending on the target's JVM configuration and available gadget chains, attackers may achieve remote code execution. This poses a significant risk to enterprise Java applications that utilize Jolokia for remote management, potentially leading to full compromise of the application server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all Jolokia instances within the network footprint. Monitor web server logs for POST requests containing \u003ccode\u003etarget.url\u003c/code\u003e parameters. Audit the Jolokia configuration to ensure that the JSR-160 proxy is disabled if not required for business operations. Apply patches provided by the Jolokia project immediately upon release to address the validation logic flaw.\u003c/p\u003e\n","date_modified":"2026-09-01T15:07:16Z","date_published":"2026-09-01T15:07:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-jolokia-jsr160-proxy-bypass/","summary":"Jolokia JSR-160 proxy contains an insufficient validation flaw, identified as CVE-2026-84218, which allows attackers to bypass denylists and trigger JNDI lookups leading to SSRF or remote code execution.","title":"Jolokia JSR-160 Proxy JNDI Injection Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-jolokia-jsr160-proxy-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Jolokia","version":"https://jsonfeed.org/version/1.1"}