CVE-2026-92609: session risk in Apache Qpid Broker-J
A notice published on September 24, 2026 describes an HTTP management authentication session-fixation flaw in Apache Qpid Broker-J through version 10.1.0. Reuse of the identifier may enable unauthorized access.
A notice published on September 24, 2026 on the oss-sec mailing list reports CVE-2026-92609, rated important in severity. The text is an automatic translation of material made available in the feed.
The described flaw affects the Apache Qpid Broker-J HTTP management plugin, identified as org.apache.qpid:qpid-broker-plugins-management-http, through version 10.1.0. According to the notice, the session is not renewed after authentication.
As a result, a remote attacker could reuse a session identifier retained after successful authentication and gain unauthorized access to a management session. The supplied text does not identify a fixed version or provide complete mitigation instructions.
To verify the issue, consult the original notice on the oss-sec mailing list and compare its details with your environment’s records and versions. Confirm remediation guidance directly with official Apache sources before changing systems; do not infer a safe version from this summary.