Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-92609: Apache Qpid Broker-J reuses session ID after login

CVE-2026-92609 · published today
Summary

When a user logs into the management interface of Apache Qpid Broker-J, the system keeps the same session identifier instead of creating a new one. This allows a remote attacker who knows the old identifier to take over the authenticated session and gain unauthorized access. Upgrade to version 10.1.1, which corrects the session handling, to protect against this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache qpid broker-j <= 10.1.0
Original advisory text
Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication.

This issue affects Apache Qpid Broker-J: through 10.1.0.

Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Severity
9.8 Critical
Type
CWE-384Session Fixation
Timeline
Published25 Sep 2026
Updated25 Sep 2026
First seen25 Sep 2026
Sources
CVE-2026-92609 · MITRE
Track software like this
Free during beta