PT-2026-30804 · Apache+1 · Apache Activemq+3

·

CVE-2026-33227

·

Published

2026-04-07

·

Updated

2026-07-27

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ Client versions prior to 5.19.3, from 6.0.0 through 6.2.2 Apache ActiveMQ Broker versions prior to 5.19.3, from 6.0.0 through 6.2.2 Apache ActiveMQ All versions prior to 5.19.3, from 6.0.0 through 6.2.2
Description An improper validation and restriction of a classpath path name issue exists in Apache ActiveMQ Client, Broker, and All. An authenticated user-supplied 'key' value can be crafted to traverse the classpath due to path concatenation, potentially leading to a classpath path resource loading issue that could be chained with another attack.
Recommendations Upgrade to version 5.19.4 or 6.2.3 to resolve the issue. Note that versions 5.19.3 and 6.2.2 also address this issue, but only in non-Windows environments.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2026-33227
CVE-2026-33227
GHSA-H2H4-5M64-M273
OESA-2026-2124
OESA-2026-2125
OESA-2026-2126
OESA-2026-2127

Affected Products

Apache Activemq
Apache Activemq Broker
Apache Activemq Client
Red Os