Description
IBM Verify Identity Access containers may not apply management password change operations correctly.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stale credentials may remain valid after password changes, enabling unauthorized access.
Action: Patch Now
AI Analysis

Impact

IBM Verify Identity Access containers accept administrator password change requests but do not apply them correctly; the new password is not enforced, leaving the old password active. This flaw is associated with CWE-522, indicating that authentication credentials are not handled securely and could be reused after an attempted revocation. The vulnerability compromises the integrity of credential management but does not provide a direct path to code execution or privilege escalation.

Affected Systems

Affected products include IBM Verify Identity Access appliance version 11.0.3 IF2 and IBM Security Verify Access appliance version 10.0.9.2 IF2. Container deployments of IBM Verify Identity Access and IBM Security Verify Access are also vulnerable, with interim fix labels 11.0.3 and 10.0.9.2 respectively. All installations running these versions should be considered vulnerable until the official interim fixes are applied.

Risk and Exploitability

The CVSS score is 9.1, but an EPSS score of < 1% is published, and the vulnerability is not listed in CISA KEV, indicating no publicly known exploitation. It is inferred that the attack vector requires administrative access to the system’s management interface or API that processes password changes. An attacker with such access could trigger or observe the flaw and maintain or elevate access using the unchanged credentials. While the risk is moderate due to the low EPSS score, the persistence of unauthorized credentials warrants prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 15:54 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 Container Container Download


OpenCVE Recommended Actions

  • Download and install the IBM Verify Identity Access v11.0.3 IF2 patch for appliances and the interim fix for containers v11.0.3, as well as the IBM Security Verify Access v10.0.9.2 IF2 patch for appliances and the interim fix for containers v10.0.9.2.
  • After installing the updates, change a management password and verify that the new password is enforced and the old password is rejected.
  • If an upgrade is not feasible immediately, temporarily disable automated password change flows or enforce manual change procedures with audit logging until the fixed versions are deployed.

Generated by OpenCVE AI on September 20, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access containers may not apply management password change operations correctly.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-522
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-17T16:31:58.298Z

Reserved: 2026-06-10T17:36:43.977Z

Link: CVE-2026-11921

cve-icon Vulnrichment

Updated: 2026-09-17T16:31:53.865Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:12.797

Modified: 2026-09-17T17:16:38.113

Link: CVE-2026-11921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials