Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a denial of service due to a heap-based out-of-bounds read. A remote attacker could send a specially crafted request that causes a limited out‑of‑bounds memory read.
Published: 2026-10-08
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

IBM Verify Access and Verify Identity Access have a heap-based out-of-bounds read that can be triggered by a specially crafted request from a remote attacker. The flaw permits a limited memory read and can ultimately crash or stall the target process, leading to a denial of service. This weakness is classified as Improper Memory Access (CWE‑125).

Affected Systems

Affected versions include IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. Container deployments of these product lines are also impacted and require the updated container images supplied by IBM.

Risk and Exploitability

The CVSS score is 3.7, indicating moderate severity. No EPSS score is published, suggesting limited current exploitation evidence. The vulnerability is not listed in CISA KEV. The attack vector is remote; a crafted request sent to the vulnerable service can trigger the out-of-bounds read and cause a denial of service.

Generated by OpenCVE AI on October 9, 2026 at 00:32 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 Container: Container Download


OpenCVE Recommended Actions

  • Download and install IBM Security Verify Access v10.0.9.3 if running 10.0.x, or IBM Verify Identity Access v11.0.3.1 for the 11.0.x line, and then restart the services to apply the fix.
  • For container deployments, download the updated container image from IBM support and redeploy the container, ensuring the new image is used.
  • Until the patch is applied, isolate the vulnerable service from the network by restricting inbound connections to trusted hosts or using firewall rules to block malicious traffic.

Generated by OpenCVE AI on October 9, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a denial of service due to a heap-based out-of-bounds read. A remote attacker could send a specially crafted request that causes a limited out‑of‑bounds memory read.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T21:02:25.152Z

Reserved: 2026-06-12T14:06:44.509Z

Link: CVE-2026-12091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-10-08T21:17:54.937

Modified: 2026-10-09T14:16:42.260

Link: CVE-2026-12091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T00:45:14Z

Weaknesses