
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33227 is a classpath path traversal vulnerability in Apache ActiveMQ affecting the Client, Broker, All, and Web components. Due to improper validation of user-supplied "key" values, an authenticated attacker can traverse the classpath via path concatenation in two contexts: when creating a Stomp consumer and when browsing messages in the Web console. Affected versions include Apache ActiveMQ (all components) before 5.19.3 and from 6.0.0 before 6.2.2. It was disclosed on April 7, 2026, with credit to researcher Dawei Wang, and carries a CVSS v3.1 base score of 4.3 (Medium) (Apache Advisory, GitHub Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). When a user-controlled "key" value is concatenated into a classpath path without adequate sanitization, an attacker can craft path traversal sequences (e.g., ../) to cause the application to load arbitrary resources from the classpath. The flaw manifests in two code paths: the Stomp consumer creation flow and the Web console message browsing functionality. Notably, versions 5.19.3 and 6.2.2 partially address the issue but fail on Windows due to a path separator resolution bug, which was fully corrected in 5.19.4 and 6.2.3 (Apache Advisory, oss-security).
Successful exploitation allows an authenticated attacker to load arbitrary classpath resources, resulting in a limited confidentiality impact (CVSS C:L). While the direct impact is constrained to resource disclosure from the classpath, the advisory notes this vulnerability could be chained with other attacks to achieve broader exploitation, potentially including unauthorized access to sensitive configuration files or credentials bundled in the classpath. Integrity and availability are not directly impacted by this vulnerability alone (Apache Advisory, GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure. The vulnerability requires valid authentication credentials, which limits the attack surface. The EPSS score is approximately 0.077% (23rd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, Feedly).
admin/admin, or compromised user accounts).../../sensitive-resource) that, when concatenated with the application's base classpath path, resolves to a target resource outside the intended directory.../, %2e%2e%2f) in key or parameter fields.Apache recommends upgrading to version 5.19.4 or 6.2.3 (or later) for all affected components (activemq-client, activemq-broker, activemq-all, activemq-web). Versions 5.19.3 and 6.2.2 also address the issue but only for non-Windows environments due to a path separator bug; Windows users must upgrade to 5.19.4 or 6.2.3. As an interim measure, applying the principle of least privilege to limit authenticated user capabilities can reduce exposure (Apache Advisory, GitHub Advisory).
The vulnerability was disclosed via the oss-security mailing list by Apache ActiveMQ maintainer Christopher L. Shannon on April 6, 2026, crediting Dawei Wang as the finder. Community reaction has been relatively muted given the low-to-moderate severity rating and the authentication requirement. No significant media coverage or notable researcher commentary beyond standard vulnerability tracking has been observed (oss-security).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
activemq
devel
activemq
focal (esm-apps)
activemq
jammy
activemq
jammy (esm-apps)
activemq
noble
activemq
noble (esm-apps)
activemq
resolute
activemq
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."