- CVE ID
- CVE-2026-19651
- CVE Description
- IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
- Published
- Sep 3, 2026
- CVSS Score & Severity
7.4High
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS Score
- 0.343%
- KEV Status
Not in KEV Catalog: No known exploits
- Source
- National Vulnerability Database