CVE-2023-33246General(apache / rocketmq)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for apache rocketmq systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.  To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-09-27. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rocketmq

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
rocketmq

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-04: 2PoC Mentioned / Linked · 2026-08-04: 1Exploit Tool / Code · 2026-08-04: 108-04
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-gXcrY61 ( CVE-2021-44228 ) EGE-GH-mlHKBE9 ( CVE-2021-44228 ) EGE-GH-UkC3bPM ( CVE-2026-57827 ) EGE-GH-kQvdrdy ( CVE-2021-21972 ) EGE-GH-UzPcxEL ( CVE-2023-33246 ) ..🧵👇

    Post summary

    The post lists recent critical exploits linked to various CVEs but offers no technical details, PoCs, patches, or evidence of active exploitation.

    1101043
    29 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-UzPcxEL [CRITICAL/PoC] Linked: CVE-2023-33246 CVE-2023-33246 🔗 https://exploitgrid.net/exploits/5c09fb10-0b0e-431c-8e1d-2f7fbe815fec

    Post summary

    A PoC exploit for CVE-2023-33246 has been posted on ExploitGrid, indicating a critical vulnerability, but there is no evidence of active exploitation or patch information.

    1000029
    29 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacherocketmq---

Explore more