CVE-2026-77874

8.6

IBM · Enterprise Build of Quarkus

IBM Enterprise Build of Quarkus is vulnerable to SQL injection, allowing remote unauthenticated attackers to manipulate back-end database information.

Executive summary

A high-severity SQL injection vulnerability in IBM Enterprise Build of Quarkus allows unauthenticated remote attackers to compromise back-end database integrity and confidentiality.

Vulnerability

The application is susceptible to SQL injection, enabling an unauthenticated remote attacker to execute arbitrary SQL commands against the back-end database, potentially leading to unauthorized data access or modification.

Business impact

Successful exploitation of this vulnerability permits unauthorized access to sensitive data, modification of records, or deletion of information within the back-end database. With a CVSS score of 8.6, this flaw poses a significant risk to data integrity and business continuity, as it does not require prior authentication to execute.

Remediation

Immediate Action: Upgrade to IBM Enterprise Build of Quarkus version 3.27.5.SP2 or 3.33.3.SP2 as specified in the official vendor documentation.

Proactive Monitoring: Review database query logs for unusual syntax or high volumes of unsuccessful attempts that may indicate automated injection attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated SQL injection detection signatures to inspect and block malicious payloads directed at the application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS severity and the potential for complete database compromise, organizations must prioritize patching this vulnerability. Apply the recommended versions immediately to eliminate the injection vector and protect the integrity of the underlying database architecture.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources