OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92609

CRITICAL · CVSS 9.8 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Apache Qpid Broker-J versions up to 10.1.0 are vulnerable to session fixation attacks, allowing remote attackers to exploit retained session identifiers and gain unauthorized access to authenticated management sessions. Organizations using this software should prioritize upgrading to version 10.1.1 to mitigate the risk of unauthorized access and potential compromise of their management interfaces.

CVE
CVE-2026-92609
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%
Apache

Original NVD Description

Session fixation in HTTP management authentication allows remoteĀ attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)