CVE-2026-67593
highCVSS v3 Base Score
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
Low
Availability
High
Published: September 10, 2026 (1 days ago)
Last Modified: September 10, 2026
Vendor: Red Hat
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
An unauthenticated network attacker can delete arbitrary durable queues on any Apache Artemis broker with OpenWire protocol enabled (default). The processRemoveSubscription() method executes pre-authentication with no authorization check, and uses the internal destroyQueue(SimpleString) overload that skips security entirely. Default queues DLQ and ExpiryQueue are trivially targetable. This is unfixed in all Artemis versions through 2.55.0.
CWE
CWE-306Affected Products
Red Hat AMQ Broker 7Red Hat build of Apache Camel for Spring Boot 4Red Hat JBoss Enterprise Application Platform 7Red Hat JBoss Enterprise Application Platform 8Red Hat JBoss Enterprise Application Platform Expansion Pack