CVE-2026-92609 Qpid Broker-J Management Session Fixation Attempt

This rule detects HTTP POST requests to the Apache Qpid Broker-J Management API that include a pre-set JSESSIONID in the cookie header during a login operation, indicating an attempt to exploit CVE-2026-92609 via session fixation.