CVE-2026-19651: IBM Enterprise Build Of Quarkus

High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

Affected products

  • IBM Enterprise Build Of Quarkus: from 3.27.1, up to and including 3.27.5; from 3.33.1, up to and including 3.33.3

Published 2026-09-08. Last modified 2026-09-09.