Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Published: 2026-10-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability involves an insecure deserialization of untrusted data, allowing a remote unauthenticated attacker to execute arbitrary code. This flaw is identified as CWE‑502. Because the attacker can run code with system privileges, confidentiality, integrity, and availability are at severe risk.

Affected Systems

Affected versions include IBM Security Verify Access from 10.0 through 10.0.9.2 and IBM Verify Identity Access from 11.0 through 11.0.3, including the corresponding container offerings. The vendor provides updates: IBM Verify Identity Access v11.0.3.1 and IBM Security Verify Access v10.0.9.3.

Risk and Exploitability

The CVSS score is 9.8, indicating critical severity. The EPSS score is not available, but the issue is not yet listed in the CISA KEV catalog. Likely attack vector is the delivery of crafted serialized data over a network interface that is accessible without authentication; such a payload can trigger code execution as described. The risk remains high until the defined patches are applied.

Generated by OpenCVE AI on October 8, 2026 at 22:49 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 Container: Container Download


OpenCVE Recommended Actions

  • Upgrade IBM Verify Identity Access to version 11.0.3.1 or later.
  • Upgrade IBM Security Verify Access to version 10.0.9.3 or later.
  • Apply the corresponding updates to the container images of Verify Identity Access Container and Security Verify Access Container.
  • If immediate upgrade is not feasible, isolate or block network access to the components that perform the unsafe deserialization so that unauthenticated remote attackers cannot reach those endpoints.

Generated by OpenCVE AI on October 8, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T21:02:55.719Z

Reserved: 2026-08-24T14:20:21.881Z

Link: CVE-2026-78401

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-10-08T21:18:03.043

Modified: 2026-10-09T14:14:30.390

Link: CVE-2026-78401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T23:15:13Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data