Description
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter.



This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.



Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Published: 2026-09-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Queue Deletion
Action: Upgrade
AI Analysis

Impact

A remote attacker can send a crafted Openwire RemoveSubscriptionInfo command that causes an Artemis broker to delete a queue before the connection is authenticated or at any time thereafter. The flaw is a missing authentication weakness (CWE-306) that allows an attacker to remove a queue from the broker’s configuration, preventing messages from being delivered to that destination.

Affected Systems

The vulnerability affects Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0, all provided by the Apache Software Foundation.

Risk and Exploitability

The impact is a high CVSS score of 9.1, indicating a severe security flaw. The EPSS score is below 1%, indicating a low current exploitation probability, and the issue is not listed in CISA KEV. Based on the description, it is inferred that any client that can reach the Openwire port before authentication may cause a queue to be deleted, so the risk depends on the broker’s exposure to untrusted hosts. In environments where the broker is reachable by external clients, the risk is moderate to high.

Generated by OpenCVE AI on September 11, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache Artemis 2.57.0 to apply the vendor‑supplied fix.
  • If an upgrade is not immediately possible, restrict Openwire/TCP port access to trusted hosts.
  • Enable strict authentication and authorization on the broker so that only authorized clients can issue remove or delete commands.

Generated by OpenCVE AI on September 11, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq Artemis
Apache artemis
Vendors & Products Apache
Apache activemq Artemis
Apache artemis

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Important


Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Title Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
Weaknesses CWE-306
References

Subscriptions

Apache Activemq Artemis Artemis
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-10T15:51:10.430Z

Reserved: 2026-07-29T21:00:39.551Z

Link: CVE-2026-67593

cve-icon Vulnrichment

Updated: 2026-09-10T05:11:59.078Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T05:17:01.560

Modified: 2026-09-16T01:10:17.700

Link: CVE-2026-67593

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T05:32:43Z

Links: CVE-2026-67593 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:45:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function