Authorization Bypass Vulnerability in IBM Quarkus
CVE-2026-19651

7.4HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 September 2026

What is CVE-2026-19651?

An authorization bypass vulnerability exists in the IBM Enterprise Build of Quarkus versions 3.27.1 to 3.27.5 and 3.33.1 to 3.33.3. This security flaw allows attackers to manipulate URL query parameters, which can lead to unauthorized access. The issue stems from the incorrect mapping of values to untrusted query string input, making it possible for an attacker to bypass standard authorization checks. IBM has released corrective measures to mitigate this vulnerability. Users are advised to update their affected versions as soon as possible.

Affected Version(s)

Enterprise Build of Quarkus 3.27.1 <= 3.27.5

Enterprise Build of Quarkus 3.33.1 <= 3.33.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Read (https://github.com/Michael-JRead) , Michael Read (https://github.com/Michael-JRead)
.