VYPR
advisoryPublished Oct 6, 2026· 1 source

Critical RCE Vulnerability in Hitachi Energy SOI Exploits Apache ActiveMQ

Hitachi Energy's SOI product is vulnerable to critical remote code execution due to an embedded Apache ActiveMQ component, allowing authenticated attackers to compromise systems.

Hitachi Energy has disclosed a critical remote code execution (RCE) vulnerability, identified as CVE-2026-34197, affecting specific versions of its SOI product. The vulnerability resides within the embedded Apache ActiveMQ component, a widely used message broker. Versions 2.0.0 through 2.2.0 of Hitachi Energy's SOI are susceptible to exploitation, posing a significant risk to industrial control systems within the energy sector.

The technical details reveal that the vulnerability leverages the Jolokia JMX-HTTP bridge, a feature often used for managing ActiveMQ brokers. By default, the Jolokia access policy permits 'exec' operations on all ActiveMQ MBeans, including critical functions like BrokerService.addNetworkConnector and BrokerService.addConnector. An authenticated attacker can exploit this by sending a crafted discovery URI that manipulates the VM transport's brokerConfig parameter.

This crafted input triggers the ResourceXmlApplicationContext within Spring to load a remote Spring XML application context. Crucially, Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService can validate the configuration. This allows an attacker to execute arbitrary code on the broker's Java Virtual Machine (JVM) through bean factory methods, such as Runtime.exec(), effectively gaining control over the affected system.

The potential impact of this vulnerability is severe, affecting the confidentiality, integrity, and availability of the SOI product. Given that SOI is deployed globally within critical infrastructure sectors, particularly energy, successful exploitation could lead to significant operational disruptions and security compromises. The CVSS v3.1 score for this vulnerability is a high 8.8, underscoring its critical nature.

Hitachi Energy has acknowledged the vulnerability and is providing a vendor fix. The recommended remediation is to apply the patch SOI EP2. This patch not only upgrades the embedded Apache ActiveMQ to version 5.19.5 but also includes updates for SOI management scripts and installs an upgraded OpenJDK version 11. Furthermore, it updates the ActiveMQ client libraries within the WildFly module, addressing multiple potential attack vectors.

In addition to the vendor fix, general mitigation factors are recommended. These include minimizing network exposure for all control system devices, ensuring they are not directly accessible from the internet, and segmenting control system networks behind firewalls. Implementing secure remote access methods like VPNs, maintaining strong password policies, and regularly scanning removable media are also advised.

This advisory was reported to CISA by the Hitachi Energy Internal Team. While a patch is available, organizations using affected versions of SOI are urged to apply the update promptly to mitigate the risk of exploitation. The vulnerability highlights the ongoing security challenges associated with embedded components in industrial control systems and the importance of timely patching and robust network security practices.

Synthesized by Vypr AI