Openwire Command Vulnerability in Apache Artemis and ActiveMQ Artemis
CVE-2026-67593
9.1CRITICAL
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-67593?
A remote attacker can exploit a vulnerability in Apache Artemis and ActiveMQ Artemis by crafting a malicious Openwire RemoveSubscriptionInfo command. This exploitation allows the attacker to delete a queue on the Artemis broker during the connection authentication and authorization stage, or at any point thereafter. Users are advised to upgrade to version 2.57.0 to address this security concern.
Affected Version(s)
Apache ActiveMQ Artemis 1.0.0 <= 2.44.0
Apache ActiveMQ Artemis 2.32.0 <= 2.44.0
Apache Artemis 2.50.0 <= 2.56.0
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Daniel Birtwhistle
krsecurity(kongr)
Dilrevx, NSSL, SJTU