VYPR
advisoryPublished Oct 8, 2026· Updated Oct 10, 2026· 1 source

IBM Security Verify Access: 22 Vulnerabilities Including Critical RCE Disclosed Together

Key findings • 22 vulnerabilities disclosed simultaneously for IBM Security Verify Access and IBM Verify Identity Access. • Multiple critical vulnerabilities allow remote, unauthenticated cod…

Key findings

  • 22 vulnerabilities disclosed simultaneously for IBM Security Verify Access and IBM Verify Identity Access.
  • Multiple critical vulnerabilities allow remote, unauthenticated code execution via deserialization flaws.
  • High and critical severity flaws include authentication bypass, path traversal, and command injection.
  • Cross-site scripting (XSS) vulnerabilities affect both authenticated and unauthenticated users.
  • IBM has released patches; immediate update is recommended for all affected versions.

On October 8, 2026, a significant batch of 22 vulnerabilities was disclosed for IBM Security Verify Access and IBM Verify Identity Access, affecting versions 10.0 through 10.0.9.2 and 11.0 through 11.0.3 respectively. This coordinated disclosure event highlights several critical security weaknesses within the identity and access management solutions. The vulnerabilities span a range of severity, including multiple critical flaws that could allow remote, unauthenticated attackers to execute arbitrary code on affected systems.

Several vulnerabilities center on the deserialization of untrusted data, a known risky practice that can lead to remote code execution if not handled properly. CVE-2026-78406 and CVE-2026-78401 are critical vulnerabilities (CVSSv3 9.8) that fall into this category, potentially allowing unauthenticated attackers to compromise the system.

Another group of vulnerabilities involves authentication bypass and improper access control. CVE-2026-19498 (High, CVSSv3 8.1) and CVE-2026-16823 (Critical, CVSSv3 9.1) could allow remote attackers to bypass security restrictions due to improper authentication mechanisms. Additionally, CVE-2026-19491 (Critical, CVSSv3 9.1) specifically mentions bypassing authentication due to improper handling of credentials.

Cross-site scripting (XSS) is also a recurring theme, with CVE-2026-78407 (Medium, CVSSv3 5.4) and CVE-2026-17189 (High, CVSSv3 8.2) allowing authenticated and unauthenticated users, respectively, to inject arbitrary JavaScript code into the Web UI. CVE-2026-11936 (Medium, CVSSv3 4.9) also points to an XSS vulnerability within the local management interface in certain configurations.

Other notable vulnerabilities include path traversal (CVE-2026-19493, High, CVSSv3 7.5) which could allow arbitrary file writes, and command injection (CVE-2026-19482, High, CVSSv3 8.8) enabling remote authenticated attackers to execute arbitrary commands. Denial of Service (DoS) vulnerabilities were also disclosed, such as CVE-2026-19494 (Medium, CVSSv3 5.9) due to uncontrolled recursion and CVE-2026-12091 (Low, CVSSv3 3.7) resulting from a heap-based out-of-bounds read.

IBM has provided patches for these vulnerabilities. Users of IBM Security Verify Access and IBM Verify Identity Access are strongly advised to update to the latest available versions to mitigate these risks. The broad range of vulnerabilities, including critical remote code execution flaws, underscores the importance of timely patching for identity and access management systems.

The disclosure of these 22 vulnerabilities on a single day highlights a significant security event for IBM's identity and access management products. The presence of multiple critical vulnerabilities, particularly those allowing remote code execution and authentication bypass, poses a substantial risk to organizations relying on these solutions for securing their digital assets. Prompt application of security updates is crucial to prevent potential exploitation.

Synthesized by Vypr AI