Path traversal in ActiveMQ - CVE-2026-33227
Published: April 10, 2026
Vulnerability details
The vulnerability allows a remote user to load unintended classpath resources.
The vulnerability exists due to path traversal in Stomp consumer creation and Web console message browsing when processing an authenticated user-supplied key value. A remote user can supply a crafted key value to load unintended classpath resources.
The issue occurs in two instances: when creating a Stomp consumer and when browsing messages in the Web console, and it could potentially be chained with another attack to lead to further exploit.
Affected software
IBM Sterling Secure Proxy
IBM Qradar SIEM
IBM Cognos Command Center
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-33227
IBM Sterling Secure Proxy - update to 6.2.1.2.iFix02
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
IBM Cognos Command Center - update to 10.2.5 FP1 IF4
activemq - update to 5.19.6-1
activemq-javadoc - update to 5.19.6-1
External References
Related Security Bulletins
- Two vulnerabilities in Apache ActiveMQ
- openEuler 24.03 LTS SP3 update for activemq
- openEuler 24.03 LTS SP1 update for activemq
- openEuler 24.03 LTS update for activemq
- openEuler 22.03 LTS SP4 update for activemq
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM QRadar SIEM