CVE-2026-67593: Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Artemisto a version that resolves this vulnerability.Fixed in 2.57.0 - Upgrade
Upgrade
Apache ActiveMQ Artemisto a version that resolves this vulnerability.Fixed in 2.57.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-67593
Event History
Frequently Asked Questions
Does exploitation require valid broker credentials?
No. A remote attacker can send a crafted Openwire RemoveSubscriptionInfo command before connection authentication and authorization occur. The command can also be used after that stage.
Which deployments should be upgraded?
Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0 are affected. Upgrade to version 2.57.0, which fixes the issue.