Skip to content
IBMCVE-2026-11927

IBM Security Verify Access: injection

Medium6.5CVE-2026-11927 · Published Sep 15, 2026 · updated Sep 20, 2026

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

IBM advisory

Affected versions

PackageAffectedFixed in
Security Verify Access
Product
>= 10.0.0, <= 10.0.9.2 Interim Fix 001No fix yet
Security Verify Access Container
Product
>= 10.0.0, <= 10.0.9.2 Interim Fix 001No fix yet
Verify Identity Access
Product
>= 11.0.0, <= 11.0.3 Interim Fix 001No fix yet
Verify Identity Access Container
Product
>= 11.0.0, <= 11.0.3 Interim Fix 001No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Severity from
CISA (its enrichment of the CVE record)
Weakness
CWE-74

More IBM advisories

All IBM
Advisory
IBM Cloud Pak for Business Automation: cross-site scripting
Medium5.4Sep 15
IBM Business Automation Workflow containers and traditional: XML external entity
High7.1Sep 15
IBM Security Verify Access: denial of service
High7.5Sep 15
IBM MQ: information disclosure
High8.1Sep 15
IBM MQ: denial of service
High7.1Sep 15
IBM MQ: code execution
High8.8Sep 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.