From 2a0b83e6e8c14ea89c9f64c9d3b95e27a1ac396e Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 10 Feb 2026 17:23:23 +0530 Subject: [PATCH 1/9] Add FortiWeb authentication bypass vulnerability check Signed-off-by: Aarush --- docs/Modules.md | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/Modules.md b/docs/Modules.md index 3c66a26f2..5ec85db5b 100644 --- a/docs/Modules.md +++ b/docs/Modules.md @@ -151,6 +151,7 @@ If you want to scan all ports please define -g 1-65535 range. Otherwise Nettacke - '**exponent_cms_cve_2021_38751_vuln**' – check the target for Exponent CMS CVE-2021-38751 - '**f5_cve_2020_5902_vuln**' – check the target for F5 RCE CVE-2020-5902 vulnerability - '**forgerock_am_cve_2021_35464_vuln**' – check the target for ForgeRock AM CVE-2021-35464 +- '**fortiweb_auth_bypass_cve_2025_64446_vuln** - check for FortiWeb authentication bypass vulnerability - '**galera_webtemp_cve_2021_40960_vuln**' – check the target for Galera WebTemplate CVE-2021-40960 - '**grafana_cve_2021_43798_vuln**' – check the target for Grafana CVE-2021-43798 vulnerability - '**graphql_vuln**' – check the target for exposed GraphQL introspection endpoint From b1ffe4e499e1fb1f301286e19bdd423b8932ddf6 Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 10 Feb 2026 17:29:23 +0530 Subject: [PATCH 2/9] Remove FortiWeb auth bypass vulnerability entry Removed entry for FortiWeb authentication bypass vulnerability. Signed-off-by: Aarush --- docs/Modules.md | 1 - 1 file changed, 1 deletion(-) diff --git a/docs/Modules.md b/docs/Modules.md index 5ec85db5b..3c66a26f2 100644 --- a/docs/Modules.md +++ b/docs/Modules.md @@ -151,7 +151,6 @@ If you want to scan all ports please define -g 1-65535 range. Otherwise Nettacke - '**exponent_cms_cve_2021_38751_vuln**' – check the target for Exponent CMS CVE-2021-38751 - '**f5_cve_2020_5902_vuln**' – check the target for F5 RCE CVE-2020-5902 vulnerability - '**forgerock_am_cve_2021_35464_vuln**' – check the target for ForgeRock AM CVE-2021-35464 -- '**fortiweb_auth_bypass_cve_2025_64446_vuln** - check for FortiWeb authentication bypass vulnerability - '**galera_webtemp_cve_2021_40960_vuln**' – check the target for Galera WebTemplate CVE-2021-40960 - '**grafana_cve_2021_43798_vuln**' – check the target for Grafana CVE-2021-43798 vulnerability - '**graphql_vuln**' – check the target for exposed GraphQL introspection endpoint From 6db5ee7a84b8d3fe34529bfb5983aca0ceffc334 Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 10 Feb 2026 17:45:01 +0530 Subject: [PATCH 3/9] Fix vulnerability name in wp_plugin_cve_2021_38314.yaml Signed-off-by: Aarush --- nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml b/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml index 6b2c22f46..88df2b91a 100644 --- a/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml +++ b/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml @@ -1,5 +1,5 @@ info: - name: CVE_2021_39320_vuln + name: CVE_2021_39314_vuln author: OWASP Nettacker Team severity: 7 description: Sensitive Information Leakage - The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress From 6fd226a7ac69c0796a408ff136f2a1ea69398386 Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 10 Feb 2026 17:45:59 +0530 Subject: [PATCH 4/9] Rename CVE identifier from 39314 to 39320 Signed-off-by: Aarush --- nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml b/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml index 88df2b91a..6b2c22f46 100644 --- a/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml +++ b/nettacker/modules/vuln/wp_plugin_cve_2021_38314.yaml @@ -1,5 +1,5 @@ info: - name: CVE_2021_39314_vuln + name: CVE_2021_39320_vuln author: OWASP Nettacker Team severity: 7 description: Sensitive Information Leakage - The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress From 3895de167f5ecb08e250c55777ae3376c8429641 Mon Sep 17 00:00:00 2001 From: Aarush289 Date: Sat, 25 Apr 2026 12:00:10 +0530 Subject: [PATCH 5/9] new module added --- docs/Modules.md | 2 +- .../activemq_cve_2026_34197_jolokia_rce_vuln | 106 ++++++++++++++++++ 2 files changed, 107 insertions(+), 1 deletion(-) create mode 100644 nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce_vuln diff --git a/docs/Modules.md b/docs/Modules.md index 10cd1c6a1..864e052fb 100644 --- a/docs/Modules.md +++ b/docs/Modules.md @@ -128,7 +128,7 @@ If you want to scan all ports please define -g 1-65535 range. Otherwise Nettacke `60443, 61532, 61900, 62078, 63331, 64623, 64680, 65000, 65129, 65389]` ## Vuln Modules - +- '**activemq_cve_2026_34197_jolokia_rce_vuln**' - check Jolokia endpoint for RCE vulnerability CVE-2026-34197 - '**aiohttp_cve_2024_23334_vuln**' - check the target for CVE-2024-23334 - '**apache_ofbiz_cve_2024_38856**' - check the target for Apache OFBiz CVE-2024-38856 - '**apache_struts_vuln**' - check Apache Struts for CVE-2017-5638 diff --git a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce_vuln b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce_vuln new file mode 100644 index 000000000..e451053fd --- /dev/null +++ b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce_vuln @@ -0,0 +1,106 @@ +info: + name: activemq_cve_2026_34197_jolokia_rce_vuln + author: Nettacker Team + severity: 8.8 + description: | + Detects CVE-2026-34197 in Apache ActiveMQ Classic via Jolokia API. + The vulnerability allows execution of addNetworkConnector which can + load remote configuration via vm:// and xbean: protocol. + This module sends a safe detection payload and checks for successful + execution indicators in the response. + + reference: + - https://nvd.nist.gov/vuln/detail/CVE-2026-34197 + - https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/ + + profiles: + - vuln + - http + - high_severity + - cve + - cve2026 + - activemq + - jolokia + - rce + +payloads: + - library: http + steps: + - method: post + timeout: 10 + headers: + User-Agent: "{user_agent}" + Content-Type: "application/json" + Authorization: "Basic YWRtaW46YWRtaW4=" + ssl: false + url: + nettacker_fuzzer: + input_format: "{{schema}}://{target}:{{ports}}/api/jolokia/" + prefix: "" + suffix: "" + interceptors: + data: + schema: + - "http" + - "https" + ports: + - 8161 + - 80 + - 443 + + data: | + {{ + "type": "exec", + "mbean": "org.apache.activemq:type=Broker,brokerName=localhost", + "operation": "addNetworkConnector", + "arguments": ["static:(vm://nettacker-probe-000?brokerConfig=none)"] + }} + + response: + condition_type: and + conditions: + status_code: + regex: '200' + reverse: false + content: + regex: '(?s)(?=.*addNetworkConnector)(?=.*org.apache.activemq)' + reverse: false + + - method: post + timeout: 10 + headers: + User-Agent: "{user_agent}" + Content-Type: "application/json" + ssl: false + url: + nettacker_fuzzer: + input_format: "{{schema}}://{target}:{{ports}}/api/jolokia/" + prefix: "" + suffix: "" + interceptors: + data: + schema: + - "http" + - "https" + ports: + - 8161 + - 80 + - 443 + + data: | + {{ + "type": "exec", + "mbean": "org.apache.activemq:type=Broker,brokerName=localhost", + "operation": "addNetworkConnector", + "arguments": ["static:(vm://nettacker-probe-000?brokerConfig=none)"] + }} + + response: + condition_type: and + conditions: + status_code: + regex: '200' + reverse: false + content: + regex: '(?s)(?=.*addNetworkConnector)(?=.*org.apache.activemq)' + reverse: false \ No newline at end of file From b42e067ac6c613ce31cb0689fecdc393aae7f28a Mon Sep 17 00:00:00 2001 From: Aarush289 Date: Sat, 25 Apr 2026 12:35:51 +0530 Subject: [PATCH 6/9] description updated --- ...a_rce_vuln => activemq_cve_2026_34197_jolokia_rce.yaml} | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) rename nettacker/modules/vuln/{activemq_cve_2026_34197_jolokia_rce_vuln => activemq_cve_2026_34197_jolokia_rce.yaml} (88%) diff --git a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce_vuln b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml similarity index 88% rename from nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce_vuln rename to nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml index e451053fd..f5cba8537 100644 --- a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce_vuln +++ b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml @@ -6,8 +6,11 @@ info: Detects CVE-2026-34197 in Apache ActiveMQ Classic via Jolokia API. The vulnerability allows execution of addNetworkConnector which can load remote configuration via vm:// and xbean: protocol. - This module sends a safe detection payload and checks for successful - execution indicators in the response. + Detection is performed by invoking addNetworkConnector via the Jolokia + exec API with a benign vm:// URI (brokerConfig=none); patched brokers + (5.19.4 / 6.2.3) reject vm:// transport for this operation. + Note: on vulnerable brokers this creates a persistent network + connector entry that remains until broker restart or manual removal. reference: - https://nvd.nist.gov/vuln/detail/CVE-2026-34197 From 3b671ede55f5ac86c15cb15459b3f28d1926e232 Mon Sep 17 00:00:00 2001 From: Aarush Date: Tue, 28 Apr 2026 08:12:00 +0530 Subject: [PATCH 7/9] Add CISA reference for CVE-2026-34197 Signed-off-by: Aarush --- .../modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml index f5cba8537..d6ae4a15a 100644 --- a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml +++ b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml @@ -15,6 +15,7 @@ info: reference: - https://nvd.nist.gov/vuln/detail/CVE-2026-34197 - https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/ + - https://www.cisa.gov/news-events/alerts/2026/04/16/cisa-adds-one-known-exploited-vulnerability-catalog profiles: - vuln @@ -25,6 +26,7 @@ info: - activemq - jolokia - rce + - cisa_kev payloads: - library: http @@ -106,4 +108,4 @@ payloads: reverse: false content: regex: '(?s)(?=.*addNetworkConnector)(?=.*org.apache.activemq)' - reverse: false \ No newline at end of file + reverse: false From 582b75fb123aadd2add022607fd559993501c557 Mon Sep 17 00:00:00 2001 From: Aarush289 Date: Mon, 25 May 2026 14:52:09 +0800 Subject: [PATCH 8/9] add cleanup step --- .../activemq_cve_2026_34197_jolokia_rce.yaml | 75 +++++++++++++++++++ 1 file changed, 75 insertions(+) diff --git a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml index d6ae4a15a..de12221ed 100644 --- a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml +++ b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml @@ -71,6 +71,44 @@ payloads: regex: '(?s)(?=.*addNetworkConnector)(?=.*org.apache.activemq)' reverse: false + - method: post + timeout: 10 + headers: + User-Agent: "{user_agent}" + Content-Type: "application/json" + Authorization: "Basic YWRtaW46YWRtaW4=" + ssl: false + url: + nettacker_fuzzer: + input_format: "{{schema}}://{target}:{{ports}}/api/jolokia/" + prefix: "" + suffix: "" + interceptors: + data: + schema: + - "http" + - "https" + ports: + - 8161 + - 80 + - 443 + + data: | + {{ + "type": "exec", + "mbean": "org.apache.activemq:type=Broker,brokerName=localhost", + "operation": "removeNetworkConnector", + "arguments": ["NC"] + }} + + response: + condition_type: and + conditions: + status_code: + regex: '200' + reverse: false + log: "Removed network connector (cleanup step)" + - method: post timeout: 10 headers: @@ -109,3 +147,40 @@ payloads: content: regex: '(?s)(?=.*addNetworkConnector)(?=.*org.apache.activemq)' reverse: false + + - method: post + timeout: 10 + headers: + User-Agent: "{user_agent}" + Content-Type: "application/json" + ssl: false + url: + nettacker_fuzzer: + input_format: "{{schema}}://{target}:{{ports}}/api/jolokia/" + prefix: "" + suffix: "" + interceptors: + data: + schema: + - "http" + - "https" + ports: + - 8161 + - 80 + - 443 + + data: | + {{ + "type": "exec", + "mbean": "org.apache.activemq:type=Broker,brokerName=localhost", + "operation": "removeNetworkConnector", + "arguments": ["NC"] + }} + + response: + log: "Removed network connector (cleanup step)" + condition_type: and + conditions: + status_code: + regex: '200' + reverse: false From 4f93150ec86a0502acef79471a01b9c919da5b07 Mon Sep 17 00:00:00 2001 From: Aarush289 Date: Wed, 27 May 2026 18:02:30 +0800 Subject: [PATCH 9/9] Make cleanup step temp to have clean logs --- .../modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml index de12221ed..c205b4285 100644 --- a/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml +++ b/nettacker/modules/vuln/activemq_cve_2026_34197_jolokia_rce.yaml @@ -102,12 +102,13 @@ payloads: }} response: + save_to_temp_events_only: cleanup_step_1 condition_type: and conditions: status_code: regex: '200' reverse: false - log: "Removed network connector (cleanup step)" + - method: post timeout: 10 @@ -178,7 +179,7 @@ payloads: }} response: - log: "Removed network connector (cleanup step)" + save_to_temp_events_only: cleanup_step_2 condition_type: and conditions: status_code: