CVE-2026-19651
Awaiting Analysis Awaiting Analysis - Queue

IBM Quarkus Authorization Bypass via URL Manipulation

Vulnerability report for CVE-2026-19651, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: IBM Corporation

Description

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm enterprise_build_of_quarkus From 3.27.1 (inc) to 3.27.5 (inc)
ibm enterprise_build_of_quarkus From 3.33.1 (inc) to 3.33.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to bypass authorization by manipulating URL query parameters in IBM Enterprise Build of Quarkus. It occurs due to incorrect mapping of untrusted query string input in the Spring Web integration.

Detection Guidance

To detect this vulnerability, inspect HTTP requests for manipulated URL query parameters in applications using IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5 or 3.33.1 through 3.33.3. Check for unusual authorization bypass attempts in logs, particularly in Spring Web integration endpoints.

Impact Analysis

An attacker could gain unauthorized access to sensitive resources or perform actions they should not be able to by exploiting this flaw. This could lead to data breaches or system compromise depending on the application's functionality.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating compliance requirements such as GDPR or HIPAA. Organizations may face legal penalties or reputational damage if such breaches occur.

Mitigation Strategies

Update IBM Enterprise Build of Quarkus to versions 3.27.5.SP1 or 3.33.3.SP1 immediately to address the authorization bypass vulnerability. No workarounds are currently available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19651. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart