Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Published: 2026-10-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Untrusted Actions via CSRF
Action: Patch Promptly
AI Analysis

Impact

IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3 are vulnerable to cross‑site request forgery. This flaw allows a malicious actor to trick a logged‑in user into sending unauthorized requests that the site trusts, potentially leading to unintended state changes, data exposure, or other unauthorised actions.

Affected Systems

Affected vendors include IBM with products Security Verify Access and Verify Identity Access, both in appliance and container editions. Specific vulnerable releases are Security Verify Access 10.0 to 10.0.9.2 and Verify Identity Access 11.0 to 11.0.3. Installed versions should be compared against the official fix releases: Security Verify Access v10.0.9.3 and Verify Identity Access v11.0.3.1.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity risk. The exploitation requires a user to visit a malicious page while authenticated, making it an indirect, user‑interaction requirement. EPSS score is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Nevertheless, because CSRF can be bypassed with social engineering or compromised network traffic, organizations should not ignore it without patching.

Generated by OpenCVE AI on October 8, 2026 at 22:48 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 Container: Container Download


OpenCVE Recommended Actions

  • Upgrade IBM Verify Identity Access to version 11.0.3.1.
  • Upgrade IBM Security Verify Access to version 10.0.9.3.
  • Implement or verify CSRF token validation for all state‑changing requests and consider applying a Web Application Firewall to block suspicious CSRF traffic.

Generated by OpenCVE AI on October 8, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-352
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T21:03:04.989Z

Reserved: 2026-08-24T14:08:03.412Z

Link: CVE-2026-78388

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-10-08T21:18:02.727

Modified: 2026-10-09T14:14:45.430

Link: CVE-2026-78388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T00:15:13Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)