Description
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
Published: 2026-09-15
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Unauthorized Command Execution (Privilege Escalation)
Action: Patch Promptly
AI Analysis

Impact

IBM Verify Identity Access contains an improper validation flaw that allows an administrator to execute additional commands they are not entitled to. The vulnerability arises because user‑supplied input is not properly checked, giving an authenticated admin the ability to run arbitrary commands. This can lead to unauthorized changes to configuration, unauthorized data access, and disruption of services.

Affected Systems

The flaw affects IBM Verify Identity Access v11.0.3 Interim Fix 001 and IBM Security Verify Access v10.0.9.2 Interim Fix 001. The corresponding container images – IBM Verify Identity Access Container v11.0.3 and IBM Security Verify Access Container v10.0.9.2 – are also impacted.

Risk and Exploitability

With a CVSS score of 7.2 the vulnerability represents a high‑severity risk. No EPSS score is available and the issue is not listed in CISA KEV, indicating no confirmed exploit data. An attacker must be able to gain access to an administrator account (or supply crafted input via an authenticated interface) to exploit the flaw. Because the attack requires privileged access, the risk is high for environments where administrative interfaces are reachable remotely or locally. Prompt application of the interim fixes mitigates this risk.

Generated by OpenCVE AI on September 15, 2026 at 23:07 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Update IBM Verify Identity Access to version 11.0.3 Interim Fix 001 via IBM Fix Central.
  • Upgrade IBM Security Verify Access to version 10.0.9.2 Interim Fix 001 using the published download link.
  • For container deployments, download and deploy the updated container images from IBM’s Verify Access container documentation.

Generated by OpenCVE AI on September 15, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:33:58.329Z

Reserved: 2026-06-10T19:19:25.162Z

Link: CVE-2026-11934

cve-icon Vulnrichment

Updated: 2026-09-15T19:33:54.227Z

cve-icon NVD

Status : Received

Published: 2026-09-15T18:17:13.380

Modified: 2026-09-15T20:17:04.360

Link: CVE-2026-11934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:15:15Z

Weaknesses