Description
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication.

This issue affects Apache Qpid Broker-J: through 10.1.0.

Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Published: 2026-09-25
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access via session fixation
Action: Patch
AI Analysis

Impact

Session fixation in the HTTP management authentication flow allows remote actors to reuse a session identifier after a successful login, granting them unauthorized access to an administrative session. The flaw is identified as CWE-384 and can be exploited by an attacker who can obtain a valid session cookie and then reuse it to perform actions on the broker that require authentication.

Affected Systems

Apache Qpid Broker-J from the Apache Software Foundation is affected through version 10.1.0. The vulnerability impacts all deployments running any of these releases until the patch for 10.1.1 is applied.

Risk and Exploitability

EPSS data is not available and the flaw is not listed in the CISA KEV catalog, so the public exploitation probability is unknown. The vulnerability permits a remote attacker who can reach the broker's HTTP management port to hijack an authenticated session by reusing a session token. No CVSS score is provided, but the fact that full administrative control becomes possible makes the risk significant. The attack vector is inferred to be remote over HTTP, requiring an attacker to authenticate first and then reuse the session ID.

Generated by OpenCVE AI on September 25, 2026 at 08:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch by upgrading to Apache Qpid Broker-J 10.1.1 or later, which removes the session fixation flaw.
  • Restrict the HTTP management interface to trusted networks or require connectivity over a VPN to limit exposure to external attackers.
  • Configure the broker to regenerate session identifiers after successful authentication or enforce a strict session timeout policy to mitigate potential reuse.

Generated by OpenCVE AI on September 25, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j
References

Fri, 25 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Title Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
Weaknesses CWE-384
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-25T13:25:46.744Z

Reserved: 2026-09-16T14:02:31.719Z

Link: CVE-2026-92609

cve-icon Vulnrichment

Updated: 2026-09-25T08:14:55.285Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-25T08:16:41.203

Modified: 2026-09-25T14:17:22.317

Link: CVE-2026-92609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T09:15:19Z

Weaknesses