CVE-2026-19625
When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CWE
- CWE-284
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- IBM Enterprise Build of Quarkus
- IBM Enterprise Build of Quarkus
Weakness type
Related vulnerabilities
- CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
- CVE-2026-75998 — ColdFusion | Improper Access Control (CWE-284)
- CVE-2026-86672 — ningzichun Student Management System Backup example.7z information disclosure
- CVE-2026-81963 — Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2026-77487 — SQL Server Elevation of Privilege Vulnerability
- CVE-2026-73028 — SQL Server Elevation of Privilege Vulnerability
- CVE-2026-69282 — Microsoft Office SharePoint Remote Code Execution Vulnerability
- CVE-2026-69273 — Microsoft Office SharePoint Remote Code Execution Vulnerability