Critical Remote Code Execution Vulnerability in Hitachi Energy SOI
Hitachi Energy has disclosed a high-severity Remote Code Execution vulnerability in the Apache ActiveMQ component of its SOI product. The flaw, tracked as CVE-2026-34197, stems from improper control of code generation in the Jolokia JMX-HTTP bridge. An authenticated attacker can exploit the default access policy to execute arbitrary code on the broker's JVM, potentially compromising confidentiality, integrity, and availability. The vulnerability affects SOI versions 2.0.0 through 2.2.0 and has been assigned a CVSS v3 base score of 8.8 (HIGH).