Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-19625

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Sep 08, 2026
Vendor unknown

Description

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.

References