Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.
Published: 2026-10-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write via Path Traversal
Action: Immediate Patch
AI Analysis

Impact

A path traversal weakness in IBM Security Verify Access 10.0‑10.0.9.2 and IBM Verify Identity Access 11.0‑11.0.3 enables a remote attacker to write arbitrary files. The flaw resides in input validation for file paths (CWE‑22), allowing overwriting or creating files outside the intended directory. Successful exploitation could corrupt configuration files, replace executables, or write malicious payloads, potentially leading to system compromise or denial service.

Affected Systems

The vulnerability affects IBM Security Verify Access appliances running versions 10.0 through 10.0.9.2 and container images up to 10.0.9.2, as well as IBM Verify Identity Access appliances running versions 11.0 through 11.0.3 and container images up to 11.0.3. All impacted wrappers, including the classic and containerised deployments, must be assessed for the update requirement.

Risk and Exploitability

With a CVSS score of 7.5 the flaw is considered high impact. The EPSS score is not available, so the current exploit probability cannot be quantified, but the vulnerability is not listed in the CISA KEV catalogue, suggesting no confirmed widespread exploitation yet. Based on the description, the likely attack vector is remote, through the management or authentication interfaces exposed to the network. An attacker must be able to authenticate or send crafted requests to the vulnerable service to trigger the path traversal.

Generated by OpenCVE AI on October 8, 2026 at 22:47 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 Container: Container Download


OpenCVE Recommended Actions

  • Upgrade IBM Verify Identity Access to version 11.0.3.1.
  • Upgrade IBM Security Verify Access to version 10.0.9.3.
  • For container deployments, download and apply the corresponding container updates for IBM Security Verify Access Container 10.0.9.3 and IBM Verify Identity Access Container 11.0.3.1, or the latest patched images provided by IBM.

Generated by OpenCVE AI on October 8, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T21:03:35.179Z

Reserved: 2026-08-10T17:53:16.353Z

Link: CVE-2026-19493

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-10-08T21:17:57.203

Modified: 2026-10-09T14:15:19.050

Link: CVE-2026-19493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T23:00:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')