{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-19651","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2026-08-12T17:38:20.473Z","datePublished":"2026-09-08T20:14:12.902Z","dateUpdated":"2026-09-09T13:27:49.159Z"},"containers":{"cna":{"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2026-09-08T20:14:12.902Z"},"title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-639","description":"CWE-639 Authorization Bypass Through User-Controlled Key","type":"CWE"}]}],"affected":[{"vendor":"IBM","product":"Enterprise Build of Quarkus","versions":[{"status":"affected","version":"3.27.1","lessThanOrEqual":"3.27.5","versionType":"semver"},{"status":"affected","version":"3.33.1","lessThanOrEqual":"3.33.3","versionType":"semver"}],"cpes":["cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3:*:*:*:*:*:*:*"]}],"descriptions":[{"lang":"en","value":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3  could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3  could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.</p>"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286498","tags":["vendor-advisory","patch"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseSeverity":"HIGH","baseScore":7.4,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}}],"solutions":[{"lang":"en","value":"The issues are addressed in IBM Enterprise Build of Quarkus 3.27.5.SP1 and 3.33.3.SP1. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP1 or 3.33.3.SP1, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The issues are addressed in IBM Enterprise Build of Quarkus 3.27.5.SP1 and 3.33.3.SP1. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP1 or 3.33.3.SP1, follow the instructions in the <a href=\"https://www.ibm.com/docs/en/quarkus/3.27.x?topic=overview-learn-whats-new-in-327#proc_updating-quarkus-maven\" rel=\"nofollow\">product documentation</a>.</p>"}]}],"credits":[{"lang":"en","value":"Michael Read (https://github.com/Michael-JRead) , Michael Read (https://github.com/Michael-JRead)","type":"finder"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-09T13:27:41.882596Z","id":"CVE-2026-19651","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-09T13:27:49.159Z"}}]}}