Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-19625: CWE-284 Improper Access Control in IBM Enterprise Build of Quarkus

0
Medium
VulnerabilityCVE-2026-19625cvecve-2026-19625cwe-284
Published: 09/08/2026 (09/08/2026, 20:18:52 UTC)
Source: CVE Database V5
Vendor/Project: IBM
Product: Enterprise Build of Quarkus

Description

CVE-2026-19625 is an improper access control vulnerability in IBM's Enterprise Build of Quarkus. It occurs when multiple endpoints are secured by different OIDC provider tenants with an optional token introspection cache enabled. A valid token from one OIDC provider can be improperly used to access endpoints secured by another OIDC provider. This vulnerability affects specific versions 3.27.1 and 3.33.1 of the product and has a medium severity rating with a CVSS score of 5.3.

CVSS v3.1

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected software

Affected versions
=3.27.1=3.33.1
CPE configurations (4)
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3:*:*:*:*:*:*:*

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 20:53:11 UTC

Technical Analysis

The vulnerability arises in scenarios where a Quarkus application has multiple endpoints each secured by different OpenID Connect (OIDC) provider tenants, for example, "/oidc-provider1" secured by OIDC Provider 1 and "/oidc-provider2" secured by OIDC Provider 2. When the optional token introspection cache is enabled, a valid token issued by OIDC Provider 1, which should only grant access to "/oidc-provider1", can also be used to access "/oidc-provider2" secured by OIDC Provider 2. This represents a failure in enforcing proper access control between different OIDC tenant endpoints, categorized under CWE-284 (Improper Access Control).

Potential Impact

An attacker with a valid token from one OIDC provider tenant can gain unauthorized access to endpoints secured by a different OIDC provider tenant within the same Quarkus application. This could lead to unauthorized information disclosure or access to resources intended to be isolated per OIDC tenant. The impact is limited to confidentiality (partial information disclosure) with no integrity or availability impact reported.

Mitigation Recommendations

Patch status is not yet confirmed — no official fix or remediation guidance has been provided by IBM for this vulnerability. Users should monitor IBM's advisories for updates. In the meantime, consider disabling the optional token introspection cache if feasible or segregating OIDC provider tenants to prevent token reuse across endpoints until a fix is available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
ibm
Date Reserved
2026-08-12T15:04:25.674Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6aa07237acd9273b4931f749

Added to database: 09/08/2026, 20:38:15 UTC

Last enriched: 09/08/2026, 20:53:11 UTC

Last updated: 09/09/2026, 01:15:46 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses