When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quarkus OIDC. A shared token-introspection cache can be exploited by a remote attacker to bypass authentication across different tenants. This allows unauthorized access to resources or data, leading to a cross-tenant authentication bypass. When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Title quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm enterprise Build Of Quarkus
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm enterprise Build Of Quarkus
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Thu, 03 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Quarkus
Quarkus oidc
Vendors & Products Quarkus
Quarkus oidc

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Quarkus OIDC. A shared token-introspection cache can be exploited by a remote attacker to bypass authentication across different tenants. This allows unauthorized access to resources or data, leading to a cross-tenant authentication bypass.
Title quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache
Weaknesses CWE-524
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-09-08T20:18:52.521Z

Updated: 2026-09-08T20:18:52.521Z

Reserved: 2026-08-12T15:04:25.674Z

Link: CVE-2026-19625

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:17:05.717

Modified: 2026-09-09T15:41:55.983

Link: CVE-2026-19625

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-31T11:55:20Z

Links: CVE-2026-19625 - Bugzilla