CVE-2026-19625 is a vulnerability in IBM Enterprise Build Of Quarkus
Published on September 8, 2026
IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Vulnerability Analysis
CVE-2026-19625 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2026-19625 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2026-19625
Want to know whenever a new CVE is published for IBM Enterprise Build Of Quarkus? stack.watch will email you.
Affected Versions
IBM Enterprise Build of Quarkus:- Version 3.27.1, <= 3.27.5 is affected.
- Version 3.33.1, <= 3.33.3 is affected.