Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.
Published: 2026-10-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is caused by improper neutralization of command arguments in IBM Security Verify Access and IBM Verify Identity Access. This flaw enables a remote authenticated attacker to execute arbitrary system commands. Based on the description, it is inferred that such execution could compromise confidentiality, integrity, and availability by potentially installing malware, exfiltrating data, or disrupting services. The weakness is classified as CWE‑88 and represents a classic command injection that requires successful authentication before exploitation.

Affected Systems

Affected products are IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3, including corresponding container deployments. Any deployment running these versions without the fixes is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability, and although EPSS data is not available, the absence of a KEV listing does not reduce the potential for exploitation. The attack vector is remote authenticated, meaning an attacker who can gain valid user credentials may launch the exploit with user privileges. Based on the description, it is inferred that the risk is significant for organizations that rely on these IBM Identity Access solutions, especially if default or weak credentials are used. Immediate remediation is recommended.

Generated by OpenCVE AI on October 8, 2026 at 23:13 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 Container: Container Download


OpenCVE Recommended Actions

  • Upgrade IBM Verify Identity Access to v11.0.3.1.
  • Upgrade IBM Security Verify Access to v10.0.9.3.
  • Ensure any containerized IBM Verify/Identity Access deployments are updated to the same fixed versions.

Generated by OpenCVE AI on October 8, 2026 at 23:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-88
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-09T15:13:37.300Z

Reserved: 2026-08-10T15:40:11.136Z

Link: CVE-2026-19482

cve-icon Vulnrichment

Updated: 2026-10-09T15:00:10.355Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-08T21:17:56.930

Modified: 2026-10-09T16:17:28.053

Link: CVE-2026-19482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T01:00:13Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')