Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-10-08
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting with credential exposure
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw that permits an authenticated user to embed arbitrary JavaScript in the web UI, allowing the attacker to modify application behavior and potentially expose credentials within a trusted session (CWE‑79).

Affected Systems

IBM Security Verify Access versions 10.0 through 10.0.9.2, IBM Verify Identity Access versions 11.0 through 11.0.3, and their container deployments are affected. Updated releases v10.0.9.3 for Security Verify Access and v11.0.3.1 for Verify Identity Access contain the fix.

Risk and Exploitability

With a CVSS score of 5.4 the flaw carries moderate severity and is not listed in CISA KEV. Exploitation requires a valid user account that can reach the web console; once authenticated, the attacker can inject malicious scripts that run in the victim’s browser, potentially leaking session data. The vendor advises applying the patches promptly in order to mitigate the risk.

Generated by OpenCVE AI on October 8, 2026 at 22:51 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance: Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3.1 https://www.ibm.com/support/fixcentral/swg/selectFixes IBM Security Verify Access Download IBM Security Verify Access v10.0.9.3 https://www.ibm.com/support/fixcentral/quickorder Container: Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Apply the latest IBM Verify Identity Access v11.0.3.1 and IBM Security Verify Access v10.0.9.3 updates, including container patches.
  • Restrict access to the administrative UI to the smallest necessary user group and enforce least‑privilege controls.
  • Deploy a Content Security Policy that blocks inline scripts and disallows execution of injected JavaScript, or enable the platform’s built‑in XSS filtering where available.

Generated by OpenCVE AI on October 8, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-08T21:01:40.785Z

Reserved: 2026-08-24T14:27:43.308Z

Link: CVE-2026-78407

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T21:18:03.330

Modified: 2026-10-08T21:26:32.080

Link: CVE-2026-78407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T23:15:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')