{"id":"CVE-2026-19651","title":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3  could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.","summary":"IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3  could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-639"],"vendor":"IBM","product":"Enterprise Build of Quarkus","affected":["enterprise_build_of_quarkus >= 3.27.1 <= 3.27.5","enterprise_build_of_quarkus >= 3.33.1 <= 3.33.3"],"published":"2026-09-08","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:41:55.983","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19651","references":[{"url":"https://www.ibm.com/support/pages/node/7286498","label":"psirt@us.ibm.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19651.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-19651"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-19651"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19651"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-09T13:27:41.882596Z"},"ingestedAt":"2026-09-08T21:11:12.374Z","epss":0.00264,"epssPercentile":0.16172,"slug":"CVE-2026-19651","body":"## Overview\n\nIBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3  could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-11 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19651.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}