Description
IBM Verify Identity Access is vulnerable to a buffer overflow attack.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Buffer overflow vulnerability
Action: Apply patch promptly
AI Analysis

Impact

IBM Verify Identity Access and related products are affected by a buffer overflow vulnerability. The description indicates that the software is vulnerable to a buffer overflow attack. No specific impact or exploitation scenario is detailed beyond the vulnerability type.

Affected Systems

Affected products include IBM Security Verify Access (v10.0.9.2 interim fix), IBM Verify Identity Access (v11.0.3 interim fix), and the corresponding container releases for both architecture sets. Users should verify their deployed versions against the versions listed in the IBM fix central links and update accordingly.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity vulnerability. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires the ability to send crafted input to the affected service, potentially over the network, but no specific exploit is published in this CVE payload.

Generated by OpenCVE AI on September 20, 2026 at 15:35 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Download Verify Identity Access v11.0.3 interim fix 001 from IBM FixCentral
  • Download and install IBM Security Verify Access v10.0.9.2 interim fix 001 from IBM FixCentral
  • Update any container images for Verify Identity Access or Security Verify Access to the latest version as listed in the IBM documentation or by pulling the official registry image
  • If immediate patching is not possible, restrict network access to the affected components

Generated by OpenCVE AI on September 20, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access is vulnerable to a buffer overflow attack.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-17T16:27:48.235Z

Reserved: 2026-06-10T18:36:09.735Z

Link: CVE-2026-11928

cve-icon Vulnrichment

Updated: 2026-09-17T16:27:43.061Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:13.180

Modified: 2026-09-17T17:16:38.307

Link: CVE-2026-11928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:45:17Z

Weaknesses