Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-67593
Apache Artemis OpenWire RemoveSubscriptionInfo can delete a queue before authentication
Technology
ActiveMQ Artemis
CVSS Score
9.1 / 10.0
Affected Versions
Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0
Upstream Fix
2.57.0
Published
September 10, 2026
OSSeva Coverage
Fixed upstream
Description
A remote attacker can send a crafted OpenWire RemoveSubscriptionInfo command that deletes a queue on the broker, before authentication and authorization or at any point after. The advisory covers the OpenWire protocol modules, including the Jakarta variant from 2.32.0.
Is your ActiveMQ Artemis deployment affected?
If you're running Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0, you need this patch. Book a discovery call to get covered.