---
id: CVE-2026-19651
title: >-
  IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through
  3.33.3  could allow an attacker to bypass authorization by manipulating URL
  query parameters due to incorrect mapping of values to untrusted query string
  input.
summary: >-
  IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through
  3.33.3  could allow an attacker to bypass authorization by manipulating URL
  query parameters due to incorrect mapping of values to untrusted query string
  input.
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-639
vendor: IBM
product: Enterprise Build of Quarkus
affected:
  - enterprise_build_of_quarkus >= 3.27.1 <= 3.27.5
  - enterprise_build_of_quarkus >= 3.33.1 <= 3.33.3
published: '2026-09-08'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:41:55.983'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19651'
references:
  - url: 'https://www.ibm.com/support/pages/node/7286498'
    label: psirt@us.ibm.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19651.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-19651'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-19651'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19651'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T13:27:41.882596Z'
ingestedAt: '2026-09-08T21:11:12.374Z'
epss: 0.00264
epssPercentile: 0.16248
---

## Overview

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3  could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · updated 2026-09-11 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19651.json)
