Session Fixation Vulnerability in Apache Qpid Broker-J
CVE-2026-92609

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
25 September 2026

What is CVE-2026-92609?

The Apache Qpid Broker-J is prone to a session fixation vulnerability which permits remote attackers to exploit authenticated sessions through the reuse of a session identifier. This flaw enables unauthorized users to gain access to management interfaces, posing a severe risk to the application's integrity. Users are strongly advised to upgrade to version 10.1.1 to mitigate this issue and secure their sessions.

Affected Version(s)

Apache Qpid Broker-J 0 <= 10.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhishek Kushwaha
.