Apache · Apache Qpid Broker-J · CVE-2026-92609
**Name of the Vulnerable Software and Affected Versions**
Apache Qpid Broker-J versions prior to 10.1.1
**Description**
Session fixation in the HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session. This occurs because the system reuses a session identifier that is retained across successful authentication, enabling session hijacking without requiring credentials.
**Recommendations**
Upgrade to version 10.1.1.