All CVEs
Vulnerability intelligence

CVE-2026-92609

Apache Software Foundation Apache Qpid Broker-J CWE-384

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.2%
Riskier than 8% of all CVEs · checked 2026-09-25
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Sep 25, 2026 · latest Sep 25, 2026

Coverage timeline

Related CVEs — Apache Software Foundation