Description
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
Published: 2026-09-08
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

The issues are addressed in IBM Enterprise Build of Quarkus 3.27.5.SP1 and 3.33.3.SP1. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP1 or 3.33.3.SP1, follow the instructions in the product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in quarkus-spring-web. A remote attacker could exploit this vulnerability by manipulating the URL query string. The system incorrectly reads the URL query string as a request header, which can lead to an authorization bypass, allowing unauthorized access to resources. IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
Title quarkus-spring-web: quarkus-spring-web: Authorization bypass via URL query string manipulation IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm enterprise Build Of Quarkus
Weaknesses CWE-639
CPEs cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm enterprise Build Of Quarkus
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Thu, 03 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Quarkus
Quarkus quarkus-spring-web
Vendors & Products Quarkus
Quarkus quarkus-spring-web

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in quarkus-spring-web. A remote attacker could exploit this vulnerability by manipulating the URL query string. The system incorrectly reads the URL query string as a request header, which can lead to an authorization bypass, allowing unauthorized access to resources.
Title quarkus-spring-web: quarkus-spring-web: Authorization bypass via URL query string manipulation
Weaknesses CWE-551
References
Metrics threat_severity

None

threat_severity

Important


Subscriptions

Ibm Enterprise Build Of Quarkus
Quarkus Quarkus-spring-web
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-09T13:27:49.159Z

Reserved: 2026-08-12T17:38:20.473Z

Link: CVE-2026-19651

cve-icon Vulnrichment

Updated: 2026-09-09T13:27:46.547Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:17:06.777

Modified: 2026-09-09T15:41:55.983

Link: CVE-2026-19651

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-31T11:29:32Z

Links: CVE-2026-19651 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:30:09Z

Weaknesses