OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-77874

HIGH · CVSS 8.6 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.5.SP1 and 3.33.1 through 3.33.3.SP1 are susceptible to SQL injection vulnerabilities, enabling remote unauthenticated attackers to execute malicious SQL queries. This could lead to unauthorized access, manipulation, or deletion of data in the back-end database. Organizations using these specific versions should prioritize patching to mitigate potential data breaches and integrity issues.

CVE
CVE-2026-77874
Severity
HIGH
CVSS
8.6
EPSS
0.43%

Original NVD Description

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.