THREAT OPS › Threat News › [NVD] CVE-2026-39852 (HIGH 8.2) — Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged user
[NVD] CVE-2026-39852 (HIGH 8.2) — Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged user
CVE-2026-39852 CVSS: 8.2 HIGH Published: 2026-05-05T21:16:22.823
Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP path-based authorization policies. Qu
Indicators of compromise
- CVE-2026-39852cve
- 3.20.6.1ipv4
- 3.27.3.1ipv4
- 3.33.1.1ipv4
- 3.35.1.1ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-39852