← Vulnerability feed

Vulnerability record · CVE-2023-37582 · published 12 July 2023

CVE-2023-37582: Apache RocketMQ NameServer incomplete fix allows remote command execution

Apache · Rocketmq

CVE-2023-37582 is a remote command execution flaw in the Apache RocketMQ NameServer component, arising because the fix for CVE-2023-33246 was incomplete in version 5.1.1. When a NameServer address is exposed and lacks permission verification, an attacker can abuse the update configuration function to run commands as the RocketMQ service account.

9.8 CVSS 3.1 Critical EPSS 90% · top 0.2% CWE-94 · Code injection
9.8CVSS 3.1 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction required, and very high EPSS probability make this a top remediation priority despite no KEV listing.

What it is

CVE-2023-37582 is a remote command execution flaw in the Apache RocketMQ NameServer component, arising because the fix for CVE-2023-33246 was incomplete in version 5.1.1. When a NameServer address is exposed and lacks permission verification, an attacker can abuse the update configuration function to run commands as the RocketMQ service account.

Impact

An attacker gains arbitrary command execution with the privileges of the RocketMQ system user, which can lead to full compromise of the host and any data or services it can reach.

Attack surface

Reachable over the network via the NameServer component when its address is exposed to the extranet and permission verification is absent; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high at 0.904 (99.8th percentile), and references are patch and advisory only with no public exploit tag.

What to do

  • Upgrade RocketMQ NameServer to 5.1.2 or above for 5.x, or 4.9.7 or above for 4.x, as the vendor recommends.
  • Do not expose NameServer addresses to untrusted networks; restrict access with firewall rules or network segmentation.
  • Enable and enforce permission verification on the NameServer component where supported.
  • Run RocketMQ under a least-privileged dedicated service account to limit command execution impact.
  • Monitor for unexpected configuration changes on NameServer instances.

Detection

  • Alert on NameServer update configuration requests originating from unexpected or external source addresses.
  • Monitor RocketMQ service account processes for anomalous child processes or command execution.
  • Review network logs for external connections to NameServer ports that should be internal only.
  • Audit NameServer configuration changes and correlate them with process execution events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-37582 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-33246Apache RocketMQ Missing Authentication Leads to Remote Command ExecutionRocketMQ 5.1.0 and below expose NameServer, Broker, and Controller components without permission verification, allowing an attacker to abuse the upda…KEVEPSS 97%analysed8.8CVE-2024-23321Apache rocketmq information exposure vulnerabilityFor RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to an unauthorized actor even i…EPSS 0.89%5.3CVE-2019-17572Apache rocketmq path traversal vulnerabilityIn Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020…EPSS 3.0%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed

Source: NIST National Vulnerability Database (record CVE-2023-37582), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.