ibm enterprise-build-of-quarkus CVE-2026-77874 is a vulnerability in IBM Enterprise Build Of Quarkus
Published on September 24, 2026

IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-77874 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
LOW
Availability Impact:
LOW

Weakness Type

What is a SQL Injection Vulnerability?

The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE-2026-77874 has been classified to as a SQL Injection vulnerability or weakness.


Products Associated with CVE-2026-77874

Want to know whenever a new CVE is published for IBM Enterprise Build Of Quarkus? stack.watch will email you.

 

Affected Versions

IBM Enterprise Build of Quarkus: