Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 may be vulnerable to audit log forgery.
Published: 2026-10-08
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: Audit Log Forgery
Action: Apply Patch
AI Analysis

Impact

IBM Security Verify Access versions 10.0 to 10.0.9.2 and IBM Verify Identity Access versions 11.0 to 11.0.3 are vulnerable to audit log forgery, which allows an attacker to inject or alter audit entries. This flaw undermines the integrity of security logs, potentially masking malicious activity or enabling the attacker to impersonate legitimate users. The weakness is a classic example of improper neutralization of log entries (CWE-88).

Affected Systems

The vulnerable products are IBM Verify Identity Access and IBM Security Verify Access, including their containerated forms. Affected appliance versions span 10.0.0 through 10.0.9.2 for Security Verify Access and 11.0.0 through 11.0.3 for Verify Identity Access. Corresponding container images with the same major versions are also impacted.

Risk and Exploitability

With a CVSS score of 2.7 the risk is classified as low, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog, indicating no known active exploitation at the time of this analysis. Exploitation likely requires authenticated access to the system’s logging mechanisms, as forging audit logs normally requires privileges to write to log files or system endpoints. Based on the description, the attack vector is inferred to be remote via the exposed logging interface, with the threat mainly to the integrity of audit evidence rather than direct system compromise.

Generated by OpenCVE AI on October 8, 2026 at 22:24 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 Container: Container Download


OpenCVE Recommended Actions

  • Apply the IBM Verify Identity Access v11.0.3.1 patch and update to IBM Security Verify Access v10.0.9.3 for appliance deployments.
  • For container deployments, replace the existing IBM Verify Identity Access Container and IBM Security Verify Access Container images with the latest patched versions released by IBM.
  • Verify that audit logging is correctly enabled and that logs are protected from tampering. Consider implementing additional log integrity checks or signed log entries where possible.

Generated by OpenCVE AI on October 8, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 may be vulnerable to audit log forgery.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-88
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T21:06:40.621Z

Reserved: 2026-06-10T19:46:44.066Z

Link: CVE-2026-11939

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T21:17:54.803

Modified: 2026-10-08T21:26:32.080

Link: CVE-2026-11939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T22:30:18Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')