IBMCVE-2026-11923
IBM Security Verify Access: improper authentication
High7.4CVE-2026-11923 · Published Aug 12, 2026 · updated Aug 17, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Security Verify Access Product | >= 10.0, <= 10.0.9.2 | No fix yet |
| Security Verify Access Container Product | >= 10.0, <= 10.0.9.2 | No fix yet |
| Verify Identity Access Product | >= 11.0, <= 11.0.3 | No fix yet |
| Verify Identity Access Container Product | >= 11.0, <= 11.0.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-287
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | IBM DataPower Gateway: race condition | Medium4.2 | No fix yet |
| Aug 12 | IBM Db2: buffer overflow | High8.4 | No fix yet |
| Aug 12 | IBM i: denial of service | High8.2 | No fix yet |
| Aug 12 | IBM DOORS Next: improper authentication | Critical10.0 | No fix yet |
| Aug 12 | IBM Db2: improper authorization | Medium4.3 | No fix yet |
| Aug 12 | IBM i Access Client Solutions: code execution | High7.8 | No fix yet |