{"id":"CVE-2026-84218","aliases":["GHSA-c9ff-59g8-m36q"],"title":"jolokia-service-jsr160 Incomplete target JMX Service URL deny list handling for user-controlled input","summary":"jolokia-service-jsr160 Incomplete target JMX Service URL deny list handling for user-controlled input","severity":"high","cvss":7.5,"cwe":["CWE-184"],"vendor":"jolokia","product":"org.jolokia:jolokia-service-jsr160","ecosystem":"maven","affected":["org.jolokia:jolokia-service-jsr160 < 2.6.2"],"patched":["org.jolokia:jolokia-service-jsr160 2.6.2"],"published":"2026-09-01","updated":"2026-10-07","sourceUpdated":"2026-10-07T18:04:16Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-c9ff-59g8-m36q","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84218"},{"url":"https://github.com/jolokia/jolokia/issues/1049"},{"url":"https://access.redhat.com/security/cve/CVE-2026-84218"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526752"},{"url":"https://github.com/advisories/GHSA-c9ff-59g8-m36q"},{"url":"https://jolokia.org/#jolokia_2_6_2_released_with_security_fixes"}],"tags":["ghsa","maven"],"epss":0.00949,"epssPercentile":0.60003,"ingestedAt":"2026-10-07T18:42:20.894Z","slug":"CVE-2026-84218","body":"## Overview\n\nA flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM.\n\n## Affected packages\n\n- `org.jolokia:jolokia-service-jsr160 < 2.6.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `org.jolokia:jolokia-service-jsr160 2.6.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}