PT-2026-30804 · Apache · Apache Activemq Broker+2

Dawei Wang

·

Published

2026-04-07

·

Updated

2026-05-03

·

CVE-2026-33227

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ Client versions prior to 5.19.3, from 6.0.0 through 6.2.2 Apache ActiveMQ Broker versions prior to 5.19.3, from 6.0.0 through 6.2.2 Apache ActiveMQ All versions prior to 5.19.3, from 6.0.0 through 6.2.2
Description An improper validation and restriction of a classpath path name issue exists in Apache ActiveMQ Client, Broker, and All. An authenticated user-supplied 'key' value can be crafted to traverse the classpath due to path concatenation, potentially leading to a classpath path resource loading issue that could be chained with another attack.
Recommendations Upgrade to version 5.19.4 or 6.2.3 to resolve the issue. Note that versions 5.19.3 and 6.2.2 also address this issue, but only in non-Windows environments.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2026-33227
CVE-2026-33227
GHSA-H2H4-5M64-M273
OESA-2026-2124
OESA-2026-2125
OESA-2026-2126
OESA-2026-2127

Affected Products

Apache Activemq
Apache Activemq Broker
Apache Activemq Client