Token Misuse in Quarkus Applications with Multiple OIDC Providers
CVE-2026-19625
5.3MEDIUM
What is CVE-2026-19625?
A security vulnerability in Quarkus applications occurs when multiple endpoints secured by different OIDC provider tenants allow a valid token from one provider to access resources protected by another. This situation arises when an optional token introspection cache is enabled, creating a significant risk of unauthorized access across secured endpoints.
Affected Version(s)
Enterprise Build of Quarkus 3.27.1 <= 3.27.5
Enterprise Build of Quarkus 3.33.1 <= 3.33.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Read (https://github.com/Michael-JRead) , Michael Read (https://github.com/Michael-JRead)