Description
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch promptly
AI Analysis

Impact

The vulnerability is an insufficient validation of incoming request resources in IBM Verify Identity Access and IBM Security Verify Access. An attacker can exploit this flaw to trigger a denial of service, rendering the affected service unavailable. The weakness is identified as CWE-400. The impact is limited to availability, with potential disruption to authentication and access control services.

Affected Systems

IBM Security Verify Access (version 10.0.0 and interim fix 10.0.9.2), IBM Verify Identity Access (version 11.0.0 and interim fix 11.0.3), and the corresponding container images for both products. All affected releases are listed in the provided CPE strings and vendor notes.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is <1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker who can send crafted requests to the services, triggering a denial of service. The conditions for exploitation are minimal, requiring only network access to the affected endpoints without authentication.

Generated by OpenCVE AI on September 20, 2026 at 14:55 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Apply the interim fix for IBM Verify Identity Access v11.0.3 from IBM Fix Central.
  • Apply the interim fix for IBM Security Verify Access v10.0.9.2 from IBM Fix Central.
  • Update the container images for Verify Identity Access and Security Verify Access using the links provided in the IBM documentation.

Generated by OpenCVE AI on September 20, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:37:34.556Z

Reserved: 2026-06-10T18:08:56.785Z

Link: CVE-2026-11926

cve-icon Vulnrichment

Updated: 2026-09-15T17:37:29.538Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:12.903

Modified: 2026-09-16T19:22:22.797

Link: CVE-2026-11926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption