Skip to content
IBMCVE-2026-19651

IBM Enterprise Build of Quarkus: insecure direct object reference

High7.4CVE-2026-19651 · Published Sep 8, 2026 · updated Sep 9, 2026

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

IBM advisory

Affected versions

PackageAffectedFixed in
Enterprise Build of Quarkus
Product
>= 3.27.1, <= 3.27.5No fix yet
>= 3.33.1, <= 3.33.3No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-639

More IBM advisories

All IBM
Advisory
IBM WebSphere Application Server: server-side request forgery
Medium5.3Sep 10
IBM Langflow OSS: remote code execution
Critical9.8Sep 10
IBM WebSphere Application Server: denial of service
Medium5.3Sep 10
IBM WebSphere Application Server: denial of service
Medium6.5Sep 10
IBM Enterprise Build of Quarkus: improper access control
Medium5.3Sep 8
## Summary The admin A2A-agent edit route does not enforce object ownership
High8.1Sep 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.