#VU125786 Path traversal in ActiveMQ - CVE-2026-33227
Published: April 10, 2026
ActiveMQ
Apache Foundation
Description
The vulnerability allows a remote user to load unintended classpath resources.
The vulnerability exists due to path traversal in Stomp consumer creation and Web console message browsing when processing an authenticated user-supplied key value. A remote user can supply a crafted key value to load unintended classpath resources.
The issue occurs in two instances: when creating a Stomp consumer and when browsing messages in the Web console, and it could potentially be chained with another attack to lead to further exploit.