CVE-2026-19625: IBM Enterprise Build Of Quarkus

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.

Affected products

  • IBM Enterprise Build Of Quarkus: from 3.27.1, up to and including 3.27.5; from 3.33.1, up to and including 3.33.3

Published 2026-09-08. Last modified 2026-09-10.