# CVE-2026-19651

## Summary

- **CVE ID:** CVE-2026-19651
- **Severity:** HIGH
- **CVSS Score:** 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-639
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 9, 2026

## Description

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3  could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

## Affected Products

- IBM — Enterprise Build of Quarkus (3.27.1)
- IBM — Enterprise Build of Quarkus (3.33.1)

## References

- [CNA](https://www.ibm.com/support/pages/node/7286498)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._