CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8516

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication

Apache Qpid Broker-J through version 10.1.0 contains a session fixation vulnerability in its HTTP management interface that allows remote attackers to reuse session identifiers across authentication boundaries. The HTTP session is not renewed after successful authentication, enabling attackers to hijack authenticated management sessions. Versions through 10.1.0 are affected.

Why it matters: Organizations deploying Apache Qpid Broker-J should assess whether the HTTP management interface is exposed and prioritize patching to prevent unauthorized administrative access through session reuse.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary