Description
When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-tenant authentication bypass
Action: Immediate Action
AI Analysis

Impact

The vulnerability arises when a Quarkus application that secures multiple endpoints with distinct OIDC provider tenants does not isolate the token‑introspection cache. An attacker with a valid token issued by one tenant can exploit the shared cache to access an endpoint secured by another tenant, effectively bypassing authentication boundaries. This exposes resources belonging to other tenants and is classified as CWE‑284 (Improper Access Control) and CWE‑524 (Improper Validation or Sanitization).

Affected Systems

The vulnerability affects IBM Enterprise Build of Quarkus versions 3.27.1, 3.27.5, 3.33.1, and 3.33.3, as identified by their CPEs. Deployments using a shared token‑introspection cache are potentially vulnerable until the vendor releases the fix. Any environment that relies on this feature without a tenant‑isolated cache configuration is at risk.

Risk and Exploitability

The CVSS score of 5.3 classifies this issue as moderate severity. EPSS score is not available, but the lack of a CISA KEV listing suggests that known exploits are not yet widely documented. The most likely attack vector is a remote attacker submitting crafted requests to the introspection endpoint, taking advantage of the shared cache to impersonate other tenants. Prompt remediation is advised to prevent cross‑tenant credential theft or data exfiltration.

Generated by OpenCVE AI on September 9, 2026 at 09:38 UTC.

Remediation

Vendor Solution

The issues are addressed in IBM Enterprise Build of Quarkus 3.27.5.SP1 and 3.33.3.SP1. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP1 or 3.33.3.SP1, follow the instructions in the product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .


OpenCVE Recommended Actions

  • Apply the vendor-specified fix by upgrading to IBM Enterprise Build of Quarkus version 3.27.5.SP1 or 3.33.3.SP1 as described in the IBM documentation.
  • Configure Quarkus OIDC to disable or isolate the token‑introspection cache per tenant
  • Restrict network access to the token‑introspection endpoint and monitor logs for suspicious authentication activity

Generated by OpenCVE AI on September 9, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quarkus OIDC. A shared token-introspection cache can be exploited by a remote attacker to bypass authentication across different tenants. This allows unauthorized access to resources or data, leading to a cross-tenant authentication bypass. When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Title quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm enterprise Build Of Quarkus
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm enterprise Build Of Quarkus
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Thu, 03 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Quarkus
Quarkus oidc
Vendors & Products Quarkus
Quarkus oidc

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quarkus OIDC. A shared token-introspection cache can be exploited by a remote attacker to bypass authentication across different tenants. This allows unauthorized access to resources or data, leading to a cross-tenant authentication bypass.
Title quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache
Weaknesses CWE-524
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}

threat_severity

Important


Subscriptions

Ibm Enterprise Build Of Quarkus
Quarkus Oidc
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T14:59:20.933Z

Reserved: 2026-08-12T15:04:25.674Z

Link: CVE-2026-19625

cve-icon Vulnrichment

Updated: 2026-09-09T19:16:36.947Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:17:05.717

Modified: 2026-09-10T16:17:09.417

Link: CVE-2026-19625

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-31T11:55:20Z

Links: CVE-2026-19625 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T09:45:08Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-524

    Use of Cache Containing Sensitive Information