Path traversal in ActiveMQ - CVE-2026-33227

 

Path traversal in ActiveMQ - CVE-2026-33227

Published: April 10, 2026


Vulnerability identifier: #VU125786
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33227
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to load unintended classpath resources.

The vulnerability exists due to path traversal in Stomp consumer creation and Web console message browsing when processing an authenticated user-supplied key value. A remote user can supply a crafted key value to load unintended classpath resources.

The issue occurs in two instances: when creating a Stomp consumer and when browsing messages in the Web console, and it could potentially be chained with another attack to lead to further exploit.


Affected software

ActiveMQ
IBM Sterling Secure Proxy
IBM Qradar SIEM
IBM Cognos Command Center
openEuler
activemq
activemq-javadoc

How to mitigate CVE-2026-33227

Install security update from vendor's website.

ActiveMQ - addressed in versions 5.19.4, 6.2.3
IBM Sterling Secure Proxy - update to 6.2.1.2.iFix02
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
IBM Cognos Command Center - update to 10.2.5 FP1 IF4
activemq - update to 5.19.6-1
activemq-javadoc - update to 5.19.6-1

External References

Related Security Bulletins