{"id":"CVE-2026-19625","title":"When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as \"/oidc-provider1\" that is secured by the OIDC Provider 1 and \"/oidc-provider2\" that is secured by the OIDC Provider 2, and an optional…","summary":"When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as \"/oidc-provider1\" that is secured by the OIDC Provider 1 and \"/oidc-provider2\" that is secured by the OIDC Provider 2, and an optional…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-284","CWE-524"],"vendor":"IBM","product":"Enterprise Build of Quarkus","affected":["enterprise_build_of_quarkus >= 3.27.1 <= 3.27.5","enterprise_build_of_quarkus >= 3.33.1 <= 3.33.3"],"published":"2026-09-08","updated":"2026-09-10","sourceUpdated":"2026-09-10T16:17:09.417","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19625","references":[{"url":"https://www.ibm.com/support/pages/node/7286498","label":"psirt@us.ibm.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19625.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-19625"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517693"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19625"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19625"}],"tags":["nvd","cve.org","csaf","vex","red-hat","score-dispute"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-09T19:16:31.069809Z"},"epss":0.00313,"epssPercentile":0.24403,"scores":{"nvd":5.3,"vendor":8.7,"cna":5.3},"ingestedAt":"2026-09-08T21:11:12.373Z","slug":"CVE-2026-19625","body":"## Overview\n\nWhen a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as \"/oidc-provider1\" that is secured by the OIDC Provider 1 and \"/oidc-provider2\" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access \"/oidc-provider1\" can also be used to access \"/oidc-provider2\" that is secured by another OIDC Provider 2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Red Hat build of Apicurio Registry 3 · no fix planned: Exploit Intelligence, Red Hat build of Apicurio Registry 3 · updated 2026-09-11 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19625.json)","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}