Skip to content
Rota Nacional

Cyber ·

CVE-2026-92609: session risk in Apache Qpid Broker-J

A notice published on September 24, 2026 describes an HTTP management authentication session-fixation flaw in Apache Qpid Broker-J through version 10.1.0. Reuse of the identifier may enable unauthorized access.

A notice published on September 24, 2026 on the oss-sec mailing list reports CVE-2026-92609, rated important in severity. The text is an automatic translation of material made available in the feed.

The described flaw affects the Apache Qpid Broker-J HTTP management plugin, identified as org.apache.qpid:qpid-broker-plugins-management-http, through version 10.1.0. According to the notice, the session is not renewed after authentication.

As a result, a remote attacker could reuse a session identifier retained after successful authentication and gain unauthorized access to a management session. The supplied text does not identify a fixed version or provide complete mitigation instructions.

To verify the issue, consult the original notice on the oss-sec mailing list and compare its details with your environment’s records and versions. Confirm remediation guidance directly with official Apache sources before changing systems; do not infer a safe version from this summary.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free