CVE-2023-6394

Executive Summary

CVE-2023-6394 exposes a Quarkus flaw where WebSocket GraphQL requests lacking role-based permissions bypass authentication on secured endpoints, enabling attackers to access data and functions beyond intended API permissions.


Authoritative CVE Metadata - CVSS Base Score: 7.4 (HIGH) - Published: 2023-12-09T02:15:06.747 - Last Modified: 2026-09-29T10:17:10.133

Original Description: A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions.

"You, yourself, as much as anybody in the entire universe, deserve your love and affection."

— Buddha
Source: NVD