CVE-2026-67593
A remote attacker can delete a queue on an Apache Artemis or ActiveMQ Artemis broker before authentication, causing data loss. The flaw allows the removal of queues via a crafted Openwire command. Upgrading to the patched version stops this attack.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0.
Real-world impact
An attacker could erase critical message queues, disrupting services and causing loss of data or functionality for applications relying on those queues.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability requires no authentication, has no user interaction, and can completely destroy data (integrity) and stop services (availability).
What to do about it
- 01Upgrade Apache Artemis to version 2.57.0 or later.
- 02Restart the broker to apply the update.
NVD-referenced vendor advisory
Timeline
- Sep 10, 2026 · 4d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.