Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .9657 99.9 YES
AFFECTED
Product Versions Fixed
Apache RocketMQ unspecified —
TIMELINE
May 21 Reserved by apache
May 24 Published (CNA: apache)
Sep 6 Added to CISA KEV, remediation due 2023-09-27
Description
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.
Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.
To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| May 21, 2023 | Reserved | Reserved by apache |
| May 24, 2023 | Published | Published (CNA: apache) |
| September 6, 2023 | KEV ADDED | Added to CISA KEV, remediation due 2023-09-27 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Apache Software Foundation | Apache RocketMQ | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-33246 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.