Missing Authentication for Critical Function Affecting org.apache.artemis:artemis-jakarta-openwire-protocol package, versions [2.50.0, 2.57.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.86% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEARTEMIS-20159293
  • published27 Sept 2026
  • disclosed10 Sept 2026
  • creditUnknown

Introduced: 10 Sep 2026

NewCVE-2026-67593  (opens in a new tab)
CWE-306  (opens in a new tab)

How to fix?

Upgrade org.apache.artemis:artemis-jakarta-openwire-protocol to version 2.57.0 or higher.

Overview

org.apache.artemis:artemis-jakarta-openwire-protocol is a To support OpenWire clients from an embedded broker deployed in a Jakarta environment (e.g. Spring Boot 3)

Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the Openwire RemoveSubscriptionInfo command in the protocol handling. An attacker can trigger unauthorized deletion of a queue by sending a crafted command before authentication and authorization are enforced.

CVSS Base Scores

version 4.0
version 3.1