CVE-2026-92609
Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
| CWE | CWE-384 |
| Vendor | apache software foundation |
| Product | apache qpid broker-j |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache qpid broker-j
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache qpid broker-j are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache Qpid Broker-J
0 ≤ 10.1.0
References
Credits
🔍 Abhishek Kushwaha