{"api_version":"1","generated_at":"2026-09-11T17:46:33+00:00","cve":"CVE-2026-19625","urls":{"html":"https://cve.report/CVE-2026-19625","api":"https://cve.report/api/cve/CVE-2026-19625.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-19625","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-19625"},"summary":{"title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities","description":"When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as \"/oidc-provider1\" that is secured by the OIDC Provider 1 and \"/oidc-provider2\" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access \"/oidc-provider1\" can also be used to access \"/oidc-provider2\" that is secured by another OIDC Provider 2.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-08 21:17:05","updated_at":"2026-09-10 16:17:09"},"problem_types":["CWE-284","CWE-284 CWE-284 Improper Access Control"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286498","name":"https://www.ibm.com/support/pages/node/7286498","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19625","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19625","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Enterprise Build of Quarkus","version":"affected 3.27.1 3.27.5 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Enterprise Build of Quarkus","version":"affected 3.33.1 3.33.3 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The issues are addressed in IBM Enterprise Build of Quarkus 3.27.5.SP1 and 3.33.3.SP1. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP1 or 3.33.3.SP1, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Michael Read (https://github.com/Michael-JRead) , Michael Read (https://github.com/Michael-JRead)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"19625","cve":"CVE-2026-19625","epss":"0.003130000","percentile":"0.239160000","score_date":"2026-09-10","updated_at":"2026-09-11 00:05:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-19625","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-09T19:16:31.069809Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-10T14:59:20.933Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3:*:*:*:*:*:*:*"],"product":"Enterprise Build of Quarkus","vendor":"IBM","versions":[{"lessThanOrEqual":"3.27.5","status":"affected","version":"3.27.1","versionType":"semver"},{"lessThanOrEqual":"3.33.3","status":"affected","version":"3.33.1","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Michael Read (https://github.com/Michael-JRead) , Michael Read (https://github.com/Michael-JRead)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as \"/oidc-provider1\" that is secured by the OIDC Provider 1 and \"/oidc-provider2\" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access \"/oidc-provider1\" can also be used to access \"/oidc-provider2\" that is secured by another OIDC Provider 2.</p>"}],"value":"When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as \"/oidc-provider1\" that is secured by the OIDC Provider 1 and \"/oidc-provider2\" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access \"/oidc-provider1\" can also be used to access \"/oidc-provider2\" that is secured by another OIDC Provider 2."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-08T20:18:52.521Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7286498"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The issues are addressed in IBM Enterprise Build of Quarkus 3.27.5.SP1 and 3.33.3.SP1. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP1 or 3.33.3.SP1, follow the instructions in the <a href=\"https://www.ibm.com/docs/en/quarkus/3.27.x?topic=overview-learn-whats-new-in-327#proc_updating-quarkus-maven\" rel=\"nofollow\">product documentation</a>.</p>"}],"value":"The issues are addressed in IBM Enterprise Build of Quarkus 3.27.5.SP1 and 3.33.3.SP1. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP1 or 3.33.3.SP1, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x ."}],"title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-19625","datePublished":"2026-09-08T20:18:52.521Z","dateReserved":"2026-08-12T15:04:25.674Z","dateUpdated":"2026-09-10T14:59:20.933Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-08 21:17:05","lastModifiedDate":"2026-09-10 16:17:09","problem_types":["CWE-284","CWE-284 CWE-284 Improper Access Control"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-09T19:16:31.069809Z","id":"CVE-2026-19625","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"19625","Ordinal":"1","Title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerab","CVE":"CVE-2026-19625","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"19625","Ordinal":"1","NoteData":"When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as \"/oidc-provider1\" that is secured by the OIDC Provider 1 and \"/oidc-provider2\" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access \"/oidc-provider1\" can also be used to access \"/oidc-provider2\" that is secured by another OIDC Provider 2.","Type":"Description","Title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerab"}]}}}