Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-67593

Apache Artemis OpenWire RemoveSubscriptionInfo can delete a queue before authentication

Technology

ActiveMQ Artemis

CVSS Score

9.1 / 10.0

Affected Versions

Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0

Upstream Fix

2.57.0

Published

September 10, 2026

OSSeva Coverage

Fixed upstream

Description

A remote attacker can send a crafted OpenWire RemoveSubscriptionInfo command that deletes a queue on the broker, before authentication and authorization or at any point after. The advisory covers the OpenWire protocol modules, including the Jakarta variant from 2.32.0.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0, you need this patch. Book a discovery call to get covered.