Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 local management interface in certain configurations is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-10-08
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting allowing credential disclosure within a trusted session
Action: Immediate Patch
AI Analysis

Impact

In certain configurations, the local management interface of IBM Verify Identity Access and IBM Security Verify Access is vulnerable to cross‑site scripting. An authenticated user can embed arbitrary JavaScript into the web UI, potentially altering intended functionality and exposing credentials that are stored in the trusted session. The weakness corresponds to input validation and output encoding failure (CWE‑79).

Affected Systems

IBM Verify Identity Access versions 11.0.0 through 11.0.3 and IBM Security Verify Access versions 10.0.0 through 10.0.9.2 are affected. The vendor recommends upgrading to IBM Verify Identity Access v11.0.3.1 and IBM Security Verify Access v10.0.9.3 to mitigate the flaw.

Risk and Exploitability

The CVSS score of 4.9 classifies the issue as medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a legitimately authenticated local user exploiting the management interface; therefore, the risk is limited to environments where privileged users have access to the interface. Mitigating the flaw reduces the possibility of session credentials being exfiltrated via injected scripts.

Generated by OpenCVE AI on October 8, 2026 at 22:26 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 Container: Container Download


OpenCVE Recommended Actions

  • Upgrade IBM Verify Identity Access to v11.0.3.1 and IBM Security Verify Access to v10.0.9.3
  • Restrict the local management interface to trusted administrators only and avoid exposing it to public or untrusted networks
  • Configure output encoding and a strict Content Security Policy on the web UI, and consider deploying a web application firewall with XSS protection to block injected scripts

Generated by OpenCVE AI on October 8, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 local management interface in certain configurations is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T21:02:14.417Z

Reserved: 2026-06-10T19:30:50.336Z

Link: CVE-2026-11936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-10-08T21:17:54.667

Modified: 2026-10-09T14:17:12.800

Link: CVE-2026-11936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T02:00:21Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')