CVE-2026-33227Disclosure(apache / activemq)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit. This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 and 6.2.2 also fix this issue, but that is limited to non-Windows environments due to a path separator resolution bug fixed in 5.19.4 and 6.2.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq
  • activemq_broker
  • activemq_web

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-07); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
activemqactivemq_brokeractivemq_web

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-19: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-19: 104-0704-19
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-191
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-34197: Apache ActiveMQ, Broker: Authenticated users could perform RCE via Jolokia MBeans https://www.openwall.com/lists/oss-security/2026/04/06/3 CVE-2026-33227: Apache ActiveMQ, Client, Broker, Web: Improper Limitation of a Pathname to a Restricted Directory https://www.openwall.com/lists/oss-security/2026/04/06/4

    Post summary

    The text announces two new Apache ActiveMQ vulnerabilities, detailing RCE via Jolokia MBeans and a path traversal issue, but does not mention PoCs, exploits, active attacks, or patches.

    12061951
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33227 Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All. In two instances (… https://www.cve.org/CVERecord?id=CVE-2026-33227

    Post summary

    The text reports CVE-2026-33227, describing a classpath validation flaw in Apache ActiveMQ components, and points to the CVE record for more information, without providing PoC, exploit, or patch details.

    00000199
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33227 Classpath Path Traversal Vulnerability in Apache ActiveMQ Client and Broker https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33227

    Post summary

    The post links to a CVE page for a Classpath Path Traversal flaw in Apache ActiveMQ, with no further details on exploitation or mitigation.

    0000042
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---
Appapacheactivemq_broker---
Appapacheactivemq_web---

Explore more