Description
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability in IBM Verify Identity Access originates from improper validation of user‑supplied requests, enabling an authenticated administrator to execute commands beyond their authorized scope. This flaw maps to CWE‑289, allowing the attacker to elevate privileges and potentially modify or exfiltrate system data. The impact includes compromise of confidentiality, integrity, and availability of the affected services.

Affected Systems

Affected products are IBM Verify Identity Access and IBM Security Verify Access, including their containerized variants. Versions lacking the interim fixes Access v11.0.3 IF2 and Security Verify Access v10.0.9.2 IF2—are vulnerable. The package identifiers in the CVE data reference these specific releases.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating a very low yet non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Despite the low exploit probability, the CVSS score of 8.1 indicates high severity because the flaw permits privilege escalation. An attacker who authenticates as an administrator can exploit the flawed request validation to run privileged commands, risking full compromise of affected systems. The attack surface extends across all installations of the cited products without the interim fixes.

Generated by OpenCVE AI on September 20, 2026 at 14:59 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Install IBM Verify Identity Access v11.0.3 IF2 from IBM Fix Central (https://www.ibm.com/support/fixcentral/quickorder)
  • Install IBM Security Verify Access v10.0.9.2 IF2 from IBM Fix Central (https://www.ibm.com/support/fixcentral/quickorder)
  • For container deployments, download the updated Verify Access image from IBM’s Verify Access documentation site (https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers) and redeploy the container with the new image

Generated by OpenCVE AI on September 20, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-289
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-20T00:34:18.739Z

Reserved: 2026-06-12T14:22:32.074Z

Link: CVE-2026-12101

cve-icon Vulnrichment

Updated: 2026-09-20T00:34:11.970Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:13.487

Modified: 2026-09-20T01:16:27.420

Link: CVE-2026-12101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-289

    Authentication Bypass by Alternate Name