CVE-2026-77874 is a vulnerability in IBM Enterprise Build Of Quarkus
Published on September 24, 2026
IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Vulnerability Analysis
CVE-2026-77874 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is a SQL Injection Vulnerability?
The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.
CVE-2026-77874 has been classified to as a SQL Injection vulnerability or weakness.
Products Associated with CVE-2026-77874
Want to know whenever a new CVE is published for IBM Enterprise Build Of Quarkus? stack.watch will email you.
Affected Versions
IBM Enterprise Build of Quarkus:- Version 3.27.1, <= 3.27.5.SP1 is affected.
- Version 3.33.1, <= 3.33.3.SP1 is affected.