CVE-2026-19651
גבוהה 7.4
תיאור (מקור, אנגלית)
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
מדדים
- CVSS 3.1
-
7.4 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-10/10/2026
- CWE
- CWE-639