CVE-2026-77874
published 2026-09-24CVE-2026-77874: IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker…
PriorityP260high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
EPSS
0.43%
35.4th percentile
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| candlepinproject | candlepin | — | — |
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| ibm | enterprise_build_of_quarkus | 3.27.1 – 3.27.5.SP1 | — |
| ibm | enterprise_build_of_quarkus | 3.33.1 – 3.33.3.SP1 | — |
| jboss-eap-7 | eap74-els-openjdk11-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk17-openshift-rhel8 | — | — |
| jboss-eap-7 | eap74-els-openjdk8-openshift-rhel8 | — | — |
| maven_3.9 | google-guice | — | — |
| opendaylight | opendaylight | — | — |
| rhbk-openshift-rhel9 | rhbk-openshift-rhel9 | — | — |
| rhoai | odh-trustyai-service-rhel9 | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection.
ghsa_unreviewed·2026-09-24
CVE-2026-77874 [HIGH] CWE-89 IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection.
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Red Hat
org.hibernate/hibernate-core: Hibernate ORM: SQL Injection via unescaped JSON path segment allows data exfiltration and authorization bypass
vendor_redhat·2026-09-17·CVSS 7.1
CVE-2026-77874 [HIGH] CWE-89 org.hibernate/hibernate-core: Hibernate ORM: SQL Injection via unescaped JSON path segment allows data exfiltration and authorization bypass
org.hibernate/hibernate-core: Hibernate ORM: SQL Injection via unescaped JSON path segment allows data exfiltration and authorization bypass
A flaw was found in Hibernate ORM. This vulnerability allows an authenticated attacker to inject arbitrary SQL commands into the underlying database by manipulating the JSON path argument. The issue arises from improper handling of JSON path segments in the JsonPathHelper.appendInlinedJsonPathIncludingPassingClause() method, specifically when using Oracle, DB2, or HANA database dialects. Successful exploitation can lead to authorization bypass and significant data exfiltration, enabling the attacker to access sensitive information from the database.
Statement: This flaw is rated as Important. An authenticated remote attacker can bypass authorization
No detection rules found.
No public exploits indexed.
2026-09-24
Published