CVE-2026-19625
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Summary
When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Enterprise Build of Quarkus | 3.27.1 <= 3.27.5 | affected |
| IBM | Enterprise Build of Quarkus | 3.33.1 <= 3.33.3 | affected |
Weaknesses
- CWE-284: CWE-284 Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.