CVE-2026-33227 is a classpath path traversal vulnerability affecting multiple Apache ActiveMQ components, including the Client, Broker, Web console, and All distributions. The flaw stems from improper validation of user-supplied "key" values during Stomp consumer creation and message browsing operations, allowing authenticated users to traverse the classpath through path concatenation and potentially load arbitrary classpath resources. Affected versions include ActiveMQ 5.19.0 through 5.19.2 and 6.0.0 through 6.2.1, with remediation available in versions 5.19.4 or 6.2.3. The vulnerability carries a CVSS 3.1 score of 4.3 (Medium), reflecting a network-accessible attack vector with low complexity and low privilege requirements. Exploitation requires user authentication and results in limited confidentiality impact with no integrity or availability compromise. The low environmental risk score of 38.0 and below-average EPSS percentile suggest this represents a moderate but not critical threat to most deployments. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. No public exploit code is widely available. However, organizations should prioritize patching to versions 5.19.4 or 6.2.3, noting that earlier patch versions contain a Windows-specific path separator bug that limits their effectiveness on Windows systems. Community attention appears minimal given the low EPSS score and inactive status on threat tracking lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.19.3CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.2.2CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
< 5.19.3CPE matchmatch criteria | cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.2.2CPE matchmatch criteria | cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:* | ||
< 5.19.3CPE matchmatch criteria | cpe:2.3:a:apache:activemq_web:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache ActiveMQ: Improper validation and restriction of a classpath path name
Apr 7, 2026CVE-2026-33227: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ Web: Improper Limitation of a Pathname to a Restricted Directory
Apr 6, 2026