Incomplete List of Disallowed Inputs Affecting org.jolokia:jolokia-service-jsr160 package, versions [,2.6.2)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.88% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJOLOKIA-19666140
  • published10 Sept 2026
  • disclosed1 Sept 2026
  • creditUnknown

Introduced: 1 Sep 2026

NewCVE-2026-84218  (opens in a new tab)
CWE-184  (opens in a new tab)

How to fix?

Upgrade org.jolokia:jolokia-service-jsr160 to version 2.6.2 or higher.

Overview

Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs in service/jsr160/src/main/java/org/jolokia/service/jsr160/Jsr160RequestHandler.java is vulnerable to insufficient validation of client-supplied JMX service URLs. An attacker can trigger server-side JNDI access and credential forwarding by sending a Jolokia POST request with a crafted target.url that bypasses the default LDAP denylist and is passed to JMXServiceURL and JMXConnectorFactory for the outbound connection. This lets the Jolokia agent JVM connect to attacker-controlled remote endpoints, causing SSRF and potentially remote code execution depending on the target JVM’s available classes and configuration. In affected deployments, the proxy can be abused to make the server reach internal or external JMX services the attacker chooses.

CVSS Base Scores

version 4.0
version 3.1