CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
Apache Qpid Broker-J through 10.1.0 has a session-fixation flaw in HTTP management authentication.
Apache Qpid Broker-J through 10.1.0 fails to renew the HTTP session after successful management authentication. A remote attacker who can fix a session identifier can reuse it to gain unauthorized access to an authenticated management session. The vendor rates the issue important and recommends users upgrade.