CVE-2026-67593
Analyzed Analyzed - Analysis Complete

Remote Queue Deletion in Apache Artemis

Vulnerability report for CVE-2026-67593, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-16

Assigner: Apache Software Foundation

Description

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-16
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache artemis From 2.50.0 (inc) to 2.57.0 (exc)
apache artemis From 1.0.0 (inc) to 2.44.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a remote attacker to send a specially crafted Openwire RemoveSubscriptionInfo command to Apache Artemis or ActiveMQ Artemis. This command can delete a queue on the broker either before authentication and authorization checks or at any later time. The issue affects specific versions of Artemis and ActiveMQ Artemis.

Detection Guidance

This vulnerability involves a crafted Openwire RemoveSubscriptionInfo command deleting queues before authentication. Detection requires monitoring Artemis broker logs for unexpected queue deletions or unauthorized Openwire commands. Check logs for RemoveSubscriptionInfo commands from untrusted sources or at unusual times.

Impact Analysis

An attacker could exploit this to delete important message queues, causing loss of messages, service disruption, or denial of service. This could affect message delivery, application functionality, and data availability in systems using vulnerable versions of Artemis or ActiveMQ Artemis.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized queue deletion on the Artemis broker. Unauthorized deletion of queues may lead to data loss or disruption of logging and monitoring systems, which are critical for compliance audits and data integrity under these regulations.

Mitigation Strategies

Upgrade Apache Artemis to version 2.57.0 or later and Apache ActiveMQ Artemis to version 2.45.0 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67593. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart