When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Quarkus OIDC. A shared token-introspection cache can be exploited by a remote attacker to bypass authentication across different tenants. This allows unauthorized access to resources or data, leading to a cross-tenant authentication bypass. | When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2. |
| Title | quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache | IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities |
| First Time appeared |
Ibm
Ibm enterprise Build Of Quarkus |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5:*:*:*:*:*:*:* cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm enterprise Build Of Quarkus |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 03 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quarkus
Quarkus oidc |
|
| Vendors & Products |
Quarkus
Quarkus oidc |
Tue, 01 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Quarkus OIDC. A shared token-introspection cache can be exploited by a remote attacker to bypass authentication across different tenants. This allows unauthorized access to resources or data, leading to a cross-tenant authentication bypass. | |
| Title | quarkus-oidc: Quarkus OIDC: Cross-tenant authentication bypass via shared token-introspection cache | |
| Weaknesses | CWE-524 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-09-08T20:18:52.521Z
Updated: 2026-09-08T20:18:52.521Z
Reserved: 2026-08-12T15:04:25.674Z
Link: CVE-2026-19625
No data.
Status : Awaiting Analysis
Published: 2026-09-08T21:17:05.717
Modified: 2026-09-09T15:41:55.983
Link: CVE-2026-19625