Openwire Command Vulnerability in Apache Artemis and ActiveMQ Artemis
CVE-2026-67593

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 September 2026

What is CVE-2026-67593?

A remote attacker can exploit a vulnerability in Apache Artemis and ActiveMQ Artemis by crafting a malicious Openwire RemoveSubscriptionInfo command. This exploitation allows the attacker to delete a queue on the Artemis broker during the connection authentication and authorization stage, or at any point thereafter. Users are advised to upgrade to version 2.57.0 to address this security concern.

Affected Version(s)

Apache ActiveMQ Artemis 1.0.0 <= 2.44.0

Apache ActiveMQ Artemis 2.32.0 <= 2.44.0

Apache Artemis 2.50.0 <= 2.56.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Birtwhistle
krsecurity(kongr)
Dilrevx, NSSL, SJTU
.