Description
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Parameter injection in third‑party service requests
Action: Patch Immediately
AI Analysis

Impact

IBM Security Verify Access’s reverse proxy accepts HTTP requests and forwards them to external third‑party services. A flaw in the proxy’s handling of request parameters permits an attacker to inject arbitrary parameters into the forwarded request. The injected parameters can alter how the external service processes the request, potentially exposing sensitive data or allowing unintended code execution if the external service is vulnerable to the injected input.

Affected Systems

The affected products are IBM Security Verify Access version 10.0.9.2 and IBM Verify Identity Access version 11.0.3, including their containerized deployments. All instances running older versions of these products are vulnerable.

Risk and Exploitability

The CVSS score of 6.5 and the EPSS score of < 1% indicate a moderate risk but a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves network traffic routed to the reverse proxy; an attacker must craft HTTP requests that reach the proxy and are forwarded to a third‑party service. Successful exploitation would allow the to inject or modify parameters in the forwarded request, potentially exposing data or enabling downstream code execution depending on how the target service processes the injected parameters.

Generated by OpenCVE AI on September 20, 2026 at 14:55 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Apply the IBM Verify Identity Access v11.0.3 IF2 update and IBM Security Verify Access v10.0.9.2 IF2 update from FixCentral
  • For container deployments, update to the latest container images following IBM’s documentation
  • Restrict outbound traffic from the reverse proxy to only approved third‑party endpoints via firewall rules or proxy ACLs
  • Enable detailed logging of proxy request headers and parameters and monitor for anomalies in a SIEM

Generated by OpenCVE AI on September 20, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-74
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-20T00:34:50.313Z

Reserved: 2026-06-10T18:32:11.967Z

Link: CVE-2026-11927

cve-icon Vulnrichment

Updated: 2026-09-20T00:34:44.864Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:13.070

Modified: 2026-09-20T01:16:27.227

Link: CVE-2026-11927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')