CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
Apache Qpid Broker-J through 10.1.0 has a session-fixation flaw in HTTP management authentication.
Apache Qpid Broker-J through 10.1.0 fails to renew the HTTP session after successful management authentication. A remote attacker who can fix a session identifier can reuse it to gain unauthorized access to an authenticated management session. The vendor rates the issue important and recommends users upgrade.
- Session identifier is not renewed after successful HTTP management login.
- Remote attackers can reuse a pre-auth session ID to hijack a management session.
- Affects Apache Qpid Broker-J through 10.1.0; vendor severity is important.
Vulnerabilities mentionedAll →
- CVE-2026-926099.8—Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92609 | Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a… Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue. NVD description · AI analysis pending | 9.8 |
Posted by Daniil Kirilyuk on Sep 24 Severity: important Affected versions: - Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-management-http) through 10.1.0 Description: Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended...
This source does not provide full text. Read it at seclists.org.