CVE-2026-19651: IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
Other sources
Quarkus quarkus-spring-web extension could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Enterprise Build of Quarkusto a version that resolves this vulnerability.Fixed in 3.27.5.SP1 - Upgrade
Upgrade
IBM Enterprise Build of Quarkusto a version that resolves this vulnerability.Fixed in 3.33.3.SP1
Event History
Frequently Asked Questions
Which releases need to be reviewed?
IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.5 and 3.33.1 through 3.33.3 are identified as affected.
What must an attacker be able to do to exploit this issue?
The attacker needs to manipulate URL query parameters. No privileges or user interaction are required, but exploitation has high attack complexity.
What is the potential impact?
Successful exploitation could bypass authorization controls and expose or alter information. The provided severity vector indicates high confidentiality and integrity impact, with no availability impact.