VYPR
Medium severity4.3NVD Advisory· Published Apr 7, 2026· Updated Apr 20, 2026

CVE-2026-33227

CVE-2026-33227

Description

Improper validation and restriction of a classpath path name vulnerability in

Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.

In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit.

This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Web: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ: before 5.19.3, from 6.0.0 before 6.2.2.

Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 and 6.2.2 also fix this issue, but that is limited to non-Windows environments due to a path separator resolution bug fixed in 5.19.4 and 6.2.3.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.activemq:activemq-clientMaven
< 5.19.35.19.3
org.apache.activemq:activemq-clientMaven
>= 6.0.0, < 6.2.26.2.2
org.apache.activemq:activemq-brokerMaven
< 5.19.35.19.3
org.apache.activemq:activemq-brokerMaven
>= 6.0.0, < 6.2.26.2.2
org.apache.activemq:activemq-allMaven
< 5.19.35.19.3
org.apache.activemq:activemq-allMaven
>= 6.0.0, < 6.2.26.2.2
org.apache.activemq:activemq-webMaven
< 5.19.35.19.3
org.apache.activemq:activemq-webMaven
>= 6.0.0, < 6.2.26.2.2

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.