{"api_version":"1","generated_at":"2026-10-01T05:18:45+00:00","cve":"CVE-2026-77874","urls":{"html":"https://cve.report/CVE-2026-77874","api":"https://cve.report/api/cve/CVE-2026-77874.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-77874","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-77874"},"summary":{"title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities","description":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-24 15:17:38","updated_at":"2026-09-24 19:41:16"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Primary","score":"8.6","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.6","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7289050","name":"https://www.ibm.com/support/pages/node/7289050","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-77874","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77874","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Enterprise Build of Quarkus","version":"affected 3.27.1 3.27.5.SP1 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Enterprise Build of Quarkus","version":"affected 3.33.1 3.33.3.SP1 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The issue is addressed in IBM Enterprise Build of Quarkus 3.27.5.SP2 and 3.33.3.SP2. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP2 or 3.33.3.SP2, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-77874","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-24T14:50:50.894476Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-24T14:53:15.426Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5.sp1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5.sp1:sp1:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3.sp1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3.sp1:sp1:*:*:*:*:*:*"],"product":"Enterprise Build of Quarkus","vendor":"IBM","versions":[{"lessThanOrEqual":"3.27.5.SP1","status":"affected","version":"3.27.1","versionType":"semver"},{"lessThanOrEqual":"3.33.3.SP1","status":"affected","version":"3.33.1","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.</p>"}],"value":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"dateUpdated":"2026-09-24T14:22:53.822Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7289050"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The issue is addressed in IBM Enterprise Build of Quarkus 3.27.5.SP2 and 3.33.3.SP2. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP2 or 3.33.3.SP2, follow the instructions in the <a href=\"https://www.ibm.com/docs/en/quarkus/3.27.x?topic=overview-learn-whats-new-in-327#proc_updating-quarkus-maven\" rel=\"nofollow\">product documentation</a>.</p>"}],"value":"The issue is addressed in IBM Enterprise Build of Quarkus 3.27.5.SP2 and 3.33.3.SP2. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP2 or 3.33.3.SP2, follow the instructions in the  product documentation https://www.ibm.com/docs/en/quarkus/3.27.x ."}],"title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities"}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-77874","datePublished":"2026-09-24T14:22:53.822Z","dateReserved":"2026-08-21T15:18:24.233Z","dateUpdated":"2026-09-24T14:53:15.426Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 15:17:38","lastModifiedDate":"2026-09-24 19:41:16","problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-24T14:50:50.894476Z","id":"CVE-2026-77874","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"77874","Ordinal":"1","Title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerab","CVE":"CVE-2026-77874","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"77874","Ordinal":"1","NoteData":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.","Type":"Description","Title":"IBM Enterprise Build of Quarkus is affected by multiple vulnerab"}]}}}