IBMCVE-2026-19651
IBM Enterprise Build of Quarkus: insecure direct object reference
High7.4CVE-2026-19651 · Published Sep 8, 2026 · updated Sep 9, 2026
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Enterprise Build of Quarkus Product | >= 3.27.1, <= 3.27.5 | No fix yet |
| >= 3.33.1, <= 3.33.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-639
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 10 | IBM WebSphere Application Server: server-side request forgery | Medium5.3 | No fix yet |
| Sep 10 | IBM Langflow OSS: remote code execution | Critical9.8 | No fix yet |
| Sep 10 | IBM WebSphere Application Server: denial of service | Medium5.3 | No fix yet |
| Sep 10 | IBM WebSphere Application Server: denial of service | Medium6.5 | No fix yet |
| Sep 8 | IBM Enterprise Build of Quarkus: improper access control | Medium5.3 | No fix yet |
| Sep 7 | ## Summary The admin A2A-agent edit route does not enforce object ownership | High8.1 | v1.0.7 |