IBMCVE-2026-19625
IBM Enterprise Build of Quarkus: improper access control
Medium5.3CVE-2026-19625 · Published Sep 8, 2026 · updated Sep 10, 2026
When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Enterprise Build of Quarkus Product | >= 3.27.1, <= 3.27.5 | No fix yet |
| >= 3.33.1, <= 3.33.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 10 | IBM WebSphere Application Server: server-side request forgery | Medium5.3 | No fix yet |
| Sep 10 | IBM Langflow OSS: remote code execution | Critical9.8 | No fix yet |
| Sep 10 | IBM WebSphere Application Server: denial of service | Medium5.3 | No fix yet |
| Sep 10 | IBM WebSphere Application Server: denial of service | Medium6.5 | No fix yet |
| Sep 8 | IBM Enterprise Build of Quarkus: insecure direct object reference | High7.4 | No fix yet |
| Sep 7 | ## Summary The admin A2A-agent edit route does not enforce object ownership | High8.1 | v1.0.7 |