Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33227

19
FAUCET Score

CVE-2026-33227 is a classpath path traversal vulnerability affecting multiple Apache ActiveMQ components, including the Client, Broker, Web console, and All distributions. The flaw stems from improper validation of user-supplied "key" values during Stomp consumer creation and message browsing operations, allowing authenticated users to traverse the classpath through path concatenation and potentially load arbitrary classpath resources. Affected versions include ActiveMQ 5.19.0 through 5.19.2 and 6.0.0 through 6.2.1, with remediation available in versions 5.19.4 or 6.2.3. The vulnerability carries a CVSS 3.1 score of 4.3 (Medium), reflecting a network-accessible attack vector with low complexity and low privilege requirements. Exploitation requires user authentication and results in limited confidentiality impact with no integrity or availability compromise. The low environmental risk score of 38.0 and below-average EPSS percentile suggest this represents a moderate but not critical threat to most deployments. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. No public exploit code is widely available. However, organizations should prioritize patching to versions 5.19.4 or 6.2.3, noting that earlier patch versions contain a Windows-specific path separator bug that limits their effectiveness on Windows systems. Community attention appears minimal given the low EPSS score and inactive status on threat tracking lists.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.19.3CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.2.2CPE matchmatch criteria
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*
< 5.19.3CPE matchmatch criteria
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.2.2CPE matchmatch criteria
cpe:2.3:a:apache:activemq_broker:*:*:*:*:*:*:*:*
< 5.19.3CPE matchmatch criteria
cpe:2.3:a:apache:activemq_web:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 44th percentile among its peer group of 21,957 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 5.19.3
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-clientFixed in: 6.2.2
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-brokerFixed in: 5.19.3
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-brokerFixed in: 6.2.2
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-allFixed in: 5.19.3
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-allFixed in: 6.2.2
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-webFixed in: 5.19.3
mavenpatch availablevia ghsa
Product: org.apache.activemq:activemq-webFixed in: 6.2.2
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

mavenGHSA-h2h4-5m64-m273medium

Apache ActiveMQ: Improper validation and restriction of a classpath path name

Apr 7, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10871.html

CVE-2026-33227: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ Web: Improper Limitation of a Pathname to a Restricted Directory

Apr 6, 2026

References

openwall.com / lists/oss-security/2026/04/06/4
Mailing ListThird Party Advisory
activemq.apache.org / security-advisories.data/CVE-2026-33227-announcement.txt
Vendor Advisory