PT-2026-98391 · Apache · Apache Qpid Broker-J

·

CVE-2026-92609

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Qpid Broker-J versions prior to 10.1.1
Description Session fixation in the HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session. This occurs because the system reuses a session identifier that is retained across successful authentication, enabling session hijacking without requiring credentials.
Recommendations Upgrade to version 10.1.1.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92609

Affected Products

Apache Qpid Broker-J