cbcvebase.
CVE-2026-77874
published 2026-09-24

CVE-2026-77874: IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker…

PriorityP260high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
EPSS
0.43%
35.4th percentile
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Affected

12 ranges
VendorProductVersion rangeFixed in
candlepinprojectcandlepin——
devspacesopenvsx-rhel9——
devspacespluginregistry-rhel9——
ibmenterprise_build_of_quarkus3.27.1 – 3.27.5.SP1—
ibmenterprise_build_of_quarkus3.33.1 – 3.33.3.SP1—
jboss-eap-7eap74-els-openjdk11-openshift-rhel8——
jboss-eap-7eap74-els-openjdk17-openshift-rhel8——
jboss-eap-7eap74-els-openjdk8-openshift-rhel8——
maven_3.9google-guice——
opendaylightopendaylight——
rhbk-openshift-rhel9rhbk-openshift-rhel9——
rhoaiodh-trustyai-service-rhel9——

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.