Skip to content
Threat Feed
high advisory

SQL Injection Vulnerability in IBM Enterprise Build of Quarkus

IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.5.SP1 and 3.33.1 through 3.33.3.SP1 are vulnerable to unauthenticated SQL injection, allowing attackers to access or modify back-end database content.

CVE search metadata

CVE search record: CVE-2026-77874. Severity: high. CVSS: 8.6. KEV: no. Product: Enterprise Build of Quarkus (3.27.1-3.27.5.SP1, 3.33.1-3.33.3.SP1). Brief: SQL Injection Vulnerability in IBM Enterprise Build of Quarkus. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-77874/

IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.5.SP1 and 3.33.1 through 3.33.3.SP1 are affected by a SQL injection vulnerability identified as CVE-2026-77874. This vulnerability permits a remote, unauthenticated attacker to inject malicious SQL statements into the application's processing layer. If successful, the attacker can interact directly with the underlying back-end database, potentially leading to unauthorized data exfiltration, information disclosure, data manipulation, or complete deletion of database records. Given the unauthenticated nature of the exploit, organizations utilizing these versions of the IBM Enterprise Build of Quarkus should prioritize security updates to mitigate the risk of data compromise.

Impact

Successful exploitation of this vulnerability allows unauthorized access to sensitive data stored in the application database. Depending on the database permissions and application configuration, this could result in significant data breaches, loss of integrity, or complete system compromise. The vulnerability affects a specific range of enterprise versions, making these organizations susceptible to targeted attacks focused on back-end data stores.

Recommendation

  • Upgrade the IBM Enterprise Build of Quarkus to a version that addresses CVE-2026-77874.
  • Review database logs for suspicious SQL syntax or unusual query patterns following the identification of this vulnerability.
  • Implement Web Application Firewall (WAF) rules to detect and block common SQL injection payloads targeted at application endpoints.

Mitigations

Upgrade IBM Enterprise Build of Quarkus to a patched version beyond the affected ranges.

immediate IT Operations

CVE-2026-77874