SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19651

HIGH · CVSS 7.4 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Enterprise Build of Quarkus versions 3.27.1 to 3.27.5 and 3.33.1 to 3.33.3 are vulnerable to an authorization bypass, which can be exploited by attackers through manipulation of URL query parameters. This flaw arises from improper handling of untrusted input, potentially allowing unauthorized access to sensitive resources. Organizations using these specific versions should prioritize remediation to mitigate the risk of unauthorized access.

CVE
CVE-2026-19651
Severity
HIGH
CVSS
7.4
EPSS
0.34%

Original NVD Description

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.