https://seclists.org/oss-sec/2026/q3/699: CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis: P-authentication Openwiprotocol handling can sult in queue deletion
Published Sep 9, 2026
·Updated
Affected Software
4 affected components
Apache ARTEMIS>=2.50.0<=2.56.0
Apache Artemis (Jakarta OpenWire Protocol)>=2.50.0<=2.56.0
Apache ActiveMQ Artemis>=1.0.0<=2.44.0
Apache ActiveMQ Artemis (Jakarta OpenWire Protocol)>=2.32.0<=2.44.0
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using the affected OpenWire protocol artifacts are exposed: org.apache.artemis:artemis-openwire-protocol or artemis-jakarta-openwire-protocol versions 2.50.0 through 2.56.0, and org.apache.activemq OpenWire artifacts in the listed affected ranges. The issue is on the Artemis broker's handling of OpenWire commands.
2
Does an attacker need valid broker credentials to delete a queue?
No. A remote attacker can send a crafted OpenWire RemoveSubscriptionInfo command before connection authentication and authorization occur. The command can also trigger queue deletion after those stages.
3
What is the recommended remediation?
Upgrade to version 2.57.0, which fixes the issue.