Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an authenticated user to cause a denial of service using a specially crafted HTTP query due to improper allocation of system resources
Published: 2026-10-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch ASAP
AI Analysis

Impact

The vulnerability allows an authenticated user to trigger a denial of service by sending a specially crafted HTTP query that exploits improper allocation of system resources. This leads to a loss of availability for the affected IBM Verify Identity Access and IBM Security Verify Access services, potentially disabling authentication flows for users and applications that rely on those services.

Affected Systems

IBM Verify Identity Access versions 11.0 through 11.0.3 and IBM Security Verify Access versions 10.0 through 10.0.9.2 are impacted. The corresponding container images for these products are also affected.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate severity risk. The EPSS score is not available, so the current likelihood of exploitation is uncertain, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a user with valid credentials who can submit HTTP requests to the affected services. Successful exploitation would degrade service availability and could be used as a component of a larger denial of service attack.

Generated by OpenCVE AI on October 8, 2026 at 22:48 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 Container: Container Download


OpenCVE Recommended Actions

  • Update IBM Verify Identity Access to release v11.0.3.1 and IBM Security Verify Access to v10.0.9.3 via the vendor’s download process.
  • Apply the equivalent patch to any deployed container images of IBM Verify Identity Access Container and IBM Security Verify Access Container.
  • Verify that application firewalls or rate‑limiting controls are in place to mitigate excessive resource consumption from malformed HTTP requests.
  • Monitor application logs for repeated denial of service patterns and adjust resource limits accordingly.

Generated by OpenCVE AI on October 8, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an authenticated user to cause a denial of service using a specially crafted HTTP query due to improper allocation of system resources
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-770
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T21:03:12.965Z

Reserved: 2026-08-24T14:17:15.530Z

Link: CVE-2026-78399

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-10-08T21:18:02.900

Modified: 2026-10-09T14:14:38.157

Link: CVE-2026-78399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T23:15:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling