Artemis OpenWire RemoveSubscriptionInfo Queue Deletion pre-auth (v2.50.02.56.0)
CVE-2026-67593 Published on September 10, 2026

Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

Vendor Advisory NVD

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-67593

Want to know whenever a new CVE is published for Apache Activemq Artemis? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Artemis: Apache Software Foundation Apache Artemis: Apache Software Foundation Apache ActiveMQ Artemis: Apache Software Foundation Apache ActiveMQ Artemis: