Skip to content
IBMCVE-2026-17616

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access...

Medium6.8CVE-2026-17616 · Published Aug 12, 2026 · updated Aug 17, 2026

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

IBM advisory

Affected versions

PackageAffectedFixed in
Security Verify Access
Product
>= 10.0, <= 10.0.9.2No fix yet
Security Verify Access Container
Product
>= 10.0, <= 10.0.9.2No fix yet
Verify Identity Access
Product
>= 11.0, <= 11.0.3No fix yet
Verify Identity Access Container
Product
>= 11.0, <= 11.0.3No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-310

More IBM advisories

All IBM
Advisory
IBM DataPower Gateway: race condition
Medium4.2Aug 12
IBM Db2: buffer overflow
High8.4Aug 12
IBM i: denial of service
High8.2Aug 12
IBM DOORS Next: improper authentication
Critical10.0Aug 12
IBM Db2: improper authorization
Medium4.3Aug 12
IBM i Access Client Solutions: code execution
High7.8Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.