Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-67593: Apache Artemis can delete queues via unauthenticated request

CVE-2026-67593 · published 15 days ago
Summary

A remote attacker can send a special Openwire command that removes a queue from an Apache Artemis or Apache ActiveMQ Artemis broker before the user is logged in, or at any time afterwards. This affects Artemis versions from 2.50.0 up to 2.56.0 and ActiveMQ Artemis versions from 1.0.0 up to 2.44.0. Upgrade to version 2.57.0 to stop the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache artemis <= 2.56.0
apache software foundation apache activemq artemis <= 2.44.0
apache artemis >= 1.0.0, < 2.44.0
>= 2.50.0, < 2.57.0
cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*
Original advisory text
Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter.



This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.



Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published10 Sep 2026
Updated25 Sep 2026
First seen10 Sep 2026
Sources
CVE-2026-67593 · MITRE
Track software like this
Free during beta