Description
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Cryptographic Validation Failure
Action: Patch Now
AI Analysis

Impact

IBM Security Verify Identity Access Reverse Proxy may provide weaker cryptographic validation of user-supplied data than expected when deployed in certain configurations. The vulnerability is a flaw in the cryptographic validation process, classified as CWE-327. An attacker who can influence the data sent through the reverse proxy may be able to bypass authentication or modify requests, potentially leading to unauthorized access or data disclosure.

Affected Systems

Affected products include IBM Verify Identity Access and IBM Security Verify Access, in both standard and container editions. The vulnerable releases are IBM Verify Identity Access 11.0.0–11.0.3 (interim fix 001) and IBM Security Verify Access 10.0.0–10.0.9.2 (interim fix 001); corresponding container interim fixes are also required.

Risk and Exploitability

The CVSS score of 7.5 indicates medium‑high severity. The EPSS score, at the time of analysis, is less than 1%, implying a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog, so no known active exploitation is publicly reported. Exploitation could occur over the network traffic that reaches the reverse proxy; given the cryptographic weakness, an attacker who successfully crafts tampered requests could potentially bypass authentication or modify requests, leading to unauthorized access or data disclosure.

Generated by OpenCVE AI on September 20, 2026 at 14:57 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Upgrade IBM Verify Identity Access to v11.0.3 IF2 from the IBM Fix Central link.
  • Upgrade IBM Security Verify Access to v10.0.9.2 IF2 from the IBM Fix Central link.
  • Apply the container interim fix for both Identity Access Container and Security Verify Access Container as described in the IBM Container documentation.

Generated by OpenCVE AI on September 20, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-327
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:33:26.743Z

Reserved: 2026-06-10T18:39:35.410Z

Link: CVE-2026-11929

cve-icon Vulnrichment

Updated: 2026-09-15T19:33:05.053Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:13.283

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-11929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm