Missing Authentication for Critical Function in Apache ActiveMQ Artemis and Apache Artemis - CVE-2026-67593
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to delete queues on an Artemis broker.
The vulnerability exists due to missing authentication and authorization checks in OpenWire protocol handling when processing a RemoveSubscriptionInfo command. A remote attacker can send a crafted OpenWire RemoveSubscriptionInfo command to delete queues on an Artemis broker.
Affected software
Apache Artemis