← Back to search

CVE-2026-92609

9.8 CRITICAL

Published 2026-09-25 · Updated 2026-09-25

AI risk analysis

Summary
The flaw allows remote attackers to gain unauthorized access to an authenticated management session by reusing a session identifier, posing a significant security risk.
Exploitability
Exploitation is relatively straightforward once the session identifier is obtained, requiring the attacker to intercept or guess the identifier.
Blast radius
If exploited, the attacker could gain full control over the management session, leading to potential data breaches or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Apache Qpid Broker-J version 10.1.1 or later.
auth-bypasssession-fixationmanagementnetwork

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-384

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.