Description
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Command Execution (Privilege Escalation)
Action: Patch Promptly
AI Analysis

Impact

IBM Verify Identity Access contains a CWE-285: Improper Privilege Management flaw that results from improper validation of user-supplied input, allowing an authenticated administrator to execute additional commands they are not entitled to. The vulnerability arises because the input is not properly checked, enabling administrators to run unintended commands.

Affected Systems

The flaw affects IBM Verify Identity Access 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.9.2 Interim Fix 001, as well as the corresponding container images IBM Verify Identity Access Container v11.0.3 and IBM Security Verify Access Container v10.0.9.2.

Risk and Exploitability

Based on the description, an attacker who has administrative credentials can supply crafted input to trigger unintended command execution. The CVSS score of 7.2 and an EPSS of <1% indicate a low probability of exploitation, and the vulnerability is not listed in CISA KEV. This flaw enables privilege escalation within the affected system.

Generated by OpenCVE AI on September 20, 2026 at 14:58 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Update IBM Verify Identity Access to version 11.0.3 Interim Fix 001 via IBM Fix Central.
  • Upgrade IBM Security Verify Access to version 10.0.9.2 Interim Fix 001 using the published download link.
  • Use the updated Verify Access container images and documentation to redeploy containers.

Generated by OpenCVE AI on September 20, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:33:58.329Z

Reserved: 2026-06-10T19:19:25.162Z

Link: CVE-2026-11934

cve-icon Vulnrichment

Updated: 2026-09-15T19:33:54.227Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:13.380

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-11934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses