{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-77874", "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "state": "PUBLISHED", "assignerShortName": "ibm", "dateReserved": "2026-08-21T15:18:24.233Z", "datePublished": "2026-09-24T14:22:53.822Z", "dateUpdated": "2026-09-24T14:53:15.426Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522", "shortName": "ibm", "dateUpdated": "2026-09-24T14:22:53.822Z"}, "title": "IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities", "affected": [{"vendor": "IBM", "product": "Enterprise Build of Quarkus", "versions": [{"status": "affected", "version": "3.27.1", "lessThanOrEqual": "3.27.5.SP1", "versionType": "semver"}, {"status": "affected", "version": "3.33.1", "lessThanOrEqual": "3.33.3.SP1", "versionType": "semver"}], "cpes": ["cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.1:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5.sp1:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.27.5.sp1:sp1:*:*:*:*:*:*", "cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.1:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3.sp1:*:*:*:*:*:*:*", "cpe:2.3:a:ibm:enterprise_build_of_quarkus:3.33.3.sp1:sp1:*:*:*:*:*:*"]}], "descriptions": [{"lang": "en", "value": "IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<p>IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.</p>"}]}], "references": [{"url": "https://www.ibm.com/support/pages/node/7289050", "tags": ["vendor-advisory", "patch"]}], "metrics": [{"format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}], "cvssV3_1": {"version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "LOW", "availabilityImpact": "LOW", "baseSeverity": "HIGH", "baseScore": 8.6, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"}}], "solutions": [{"lang": "en", "value": "The issue is addressed in IBM Enterprise Build of Quarkus 3.27.5.SP2 and 3.33.3.SP2. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP2 or 3.33.3.SP2, follow the instructions in the\u00a0 product documentation https://www.ibm.com/docs/en/quarkus/3.27.x .", "supportingMedia": [{"type": "text/html", "base64": false, "value": "<p>The issue is addressed in IBM Enterprise Build of Quarkus 3.27.5.SP2 and 3.33.3.SP2. To update your project to IBM Enterprise Build of Quarkus 3.27.5.SP2 or 3.33.3.SP2, follow the instructions in the\u00a0<a href=\"https://www.ibm.com/docs/en/quarkus/3.27.x?topic=overview-learn-whats-new-in-327#proc_updating-quarkus-maven\" rel=\"nofollow\">product documentation</a>.</p>"}]}]}, "adp": [{"problemTypes": [{"descriptions": [{"type": "CWE", "cweId": "CWE-89", "lang": "en", "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2026-09-24T14:50:50.894476Z", "id": "CVE-2026-77874", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-24T14:53:15.426Z"}}]}}