CVE-2026-67593
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Apache ActiveMQ Artemis is an open-source, high-performance message broker and the next-generation broker of the Apache ActiveMQ project. It provides asynchronous messaging with a non-blocking, journal-backed core and supports multiple wire protocols and APIs, including AMQP 1.0, MQTT, STOMP, OpenWire, and Jakarta Messaging (JMS). Broker and client components are published as Maven artifacts under org.apache.activemq through 2.44.0, and under org.apache.artemis from 2.50.0.
An authorization bypass vulnerability (CVE-2026-67593) has been identified in the OpenWire protocol handler of Apache ActiveMQ Artemis, which allows unauthenticated remote attackers to delete queues on the broker, including durable subscription queues and every message waiting in them. Authenticated clients can likewise delete subscriptions that belong to other clients.
Per CWE: The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
This issue affects multiple versions of Apache ActiveMQ Artemis.
Details
Module Info
- Product: Apache ActiveMQ Artemis
- Affected packages:
org.apache.activemq:artemis-openwire-protocol,org.apache.activemq:artemis-jakarta-openwire-protocol,org.apache.artemis:artemis-openwire-protocol,org.apache.artemis:artemis-jakarta-openwire-protocol - Affected versions:
org.apache.activemq:artemis-openwire-protocol: >=1.0.0 <=2.44.0org.apache.activemq:artemis-jakarta-openwire-protocol: >=2.32.0 <=2.44.0org.apache.artemis:artemis-openwire-protocol: >=2.50.0 <=2.56.0org.apache.artemis:artemis-jakarta-openwire-protocol: >=2.50.0 <=2.56.0- GitHub repository: https://github.com/apache/activemq-artemis
- Published packages: https://central.sonatype.com/artifact/org.apache.activemq/artemis-openwire-protocol, https://central.sonatype.com/artifact/org.apache.activemq/artemis-jakarta-openwire-protocol, https://central.sonatype.com/artifact/org.apache.artemis/artemis-openwire-protocol, https://central.sonatype.com/artifact/org.apache.artemis/artemis-jakarta-openwire-protocol
- Package manager: Maven
- Fixed in:
- OSS Apache ActiveMQ Artemis 2.57.0
- NES for Apache ActiveMQ Artemis v2.19.4
Vulnerability Info
This Critical-severity vulnerability is found in the org.apache.activemq:artemis-openwire-protocol, org.apache.activemq:artemis-jakarta-openwire-protocol, org.apache.artemis:artemis-openwire-protocol and org.apache.artemis:artemis-jakarta-openwire-protocol packages in multiple versions of Apache ActiveMQ Artemis. An OpenWire connection authenticates when the client sends its ConnectionInfo command, but OpenWireConnection.act() dispatches every incoming command to its handler without checking whether that exchange has happened. The handler for RemoveSubscriptionInfo then deletes the named queue through the broker's internal API, which performs no security check, rather than through the connection's authenticated session:
@Override
public Response processRemoveSubscription(RemoveSubscriptionInfo subInfo) throws Exception {
SimpleString subQueueName = org.apache.activemq.artemis.jms.client.ActiveMQDestination.createQueueNameForSubscription(true, subInfo.getClientId(), subInfo.getSubscriptionName());
server.destroyQueue(subQueueName);
return null;
}
The queue name is built entirely from the client ID and subscription name carried in the command, so an attacker who opens a TCP connection to an OpenWire acceptor and sends a single RemoveSubscriptionInfo frame chooses which queue the broker destroys. When the command carries no client ID, the queue name is the subscription name itself, so the attacker is not limited to durable subscription queues and can delete other queues on the broker by name. Because the handler never compares the command's fields with the connection's own identity, a client that has authenticated can also delete subscriptions belonging to any other client.
OpenWire is enabled by default on the artemis acceptor on port 61616, so a standalone broker reachable from an untrusted network is exposed in its default configuration. Applications that embed the broker through artemis-server alone are not exposed, because artemis-server does not depend on the OpenWire protocol module.
Mitigation
Only recent versions of Apache ActiveMQ Artemis are community-supported. Older lines are End-of-Life and will not receive public updates to address this issue.
Where upgrading is not immediately possible, remove OPENWIRE from the protocols list of every acceptor that accepts connections from untrusted sources.
NES for Apache ActiveMQ Artemis v2.19.4 ships the fix in artemis-openwire-protocol. A broker that loads the OpenWire protocol must upgrade that artifact to 2.19.1-artemis-server-2.19.4; upgrading artemis-server alone does not apply the fix.
Users of the affected components should apply one of the following mitigations:
- Upgrade Apache ActiveMQ Artemis to a currently supported release that contains the fix (2.57.0 or later), which upstream publishes under the org.apache.artemis groupId; no fixed release exists under org.apache.activemq.
- Leverage a commercial support partner like HeroDevs for post-EOL security support.
Credits
- Daniel Birtwhistle (finder)
- krsecurity(kongr) (reporter)
- Dilrevx, NSSL, SJTU (reporter)