IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
https://www.ibm.com/support/pages/node/7286498
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-74180
Source: Mitre, NVD
Published: 2026-09-08
Updated: 2026-09-09
Base Score: 7.1
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N
Severity: High
Base Score: 7.4
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS: 0.00264