CVE-2026-49270: Activemq Unsafe Factoryfinder
Instantiating a `FactoryFinder` without strict type validation allows arbitrary classpath classes to be loaded and initialized. If an attacker controls the lookup key or path, they can instantiate completely unrelated 'gadget' classes, leading to Remote Code Execution or other severe impacts. Update to use the constructor that accepts `requiredType` and `all
greprules fetch cve-2026-49270-activemq-unsafe-factoryfinder --engine opengrepDescription
Instantiating a `FactoryFinder` without strict type validation allows arbitrary classpath classes to be loaded and initialized. If an attacker controls the lookup key or path, they can instantiate completely unrelated 'gadget' classes, leading to Remote Code Execution or other severe impacts. Update to use the constructor that accepts `requiredType` and `all
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.