Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-67593: Apache Artemis can delete queues via unauthenticated request
CVE-2026-67593 · published 15 days ago
Summary
A remote attacker can send a special Openwire command that removes a queue from an Apache Artemis or Apache ActiveMQ Artemis broker before the user is logged in, or at any time afterwards. This affects Artemis versions from 2.50.0 up to 2.56.0 and ActiveMQ Artemis versions from 1.0.0 up to 2.44.0. Upgrade to version 2.57.0 to stop the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache artemis | <= 2.56.0 |
| apache software foundation | apache activemq artemis | <= 2.44.0 |
| apache | artemis |
>= 1.0.0, < 2.44.0 >= 2.50.0, < 2.57.0 cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:* |
Original advisory text
Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
References
- http://www.openwall.com/lists/oss-security/2026/09/10/6 URL
- https://repo.maven.apache.org/maven2 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67593... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-67593 Vendor Advisory
- https://lists.apache.org/thread/zlglnsg8s5xv8n56d15dm5mf00h2d8xs Vendor Advisory
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published10 Sep 2026
Updated25 Sep 2026
First seen10 Sep 2026
Track software like this
Free during beta