CVE-2026-19651
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
- Published Sep 8, 2026
- CVSS 7.4 high
- 0.3% chance of exploitation in the next 30 days (EPSS)