EXECUTIVE SUMMARY:
CVE-2026-50559 with a CVSS score of 7.5 is a high-severity authorization bypass vulnerability affecting the Quarkus framework. The flaw exists in Quarkus HTTP path-based authorization controls, where attackers can bypass configured security policies by using encoded path characters such as %3B to smuggle matrix parameters, or %2F and %5C to access protected static resources. An unauthenticated remote attacker could exploit this issue to access resources that should be restricted by authorization rules, potentially leading to unauthorized information disclosure. The vulnerability impacts affected Quarkus deployments that rely on path-based authorization mechanisms.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
CVE-2026-50559 with a CVSS score of 7.5 is a high-severity authorization bypass vulnerability affecting the Quarkus framework. The flaw exists in Quarkus HTTP path-based authorization controls, where attackers can bypass configured security policies by using encoded path characters such as %3B to smuggle matrix parameters, or %2F and %5C to access protected static resources. An unauthenticated remote attacker could exploit this issue to access resources that should be restricted by authorization rules, potentially leading to unauthorized information disclosure. The vulnerability impacts affected Quarkus deployments that rely on path-based authorization mechanisms.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
[/emaillocker]