IBMCVE-2026-4938
IBM Security Verify Access: improper authorization
Medium6.5CVE-2026-4938 · Published Jul 17, 2026 · updated Jul 30, 2026
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned permissions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Security Verify Access Product | >= 10.0, <= 10.0.9.1 | No fix yet |
| Security Verify Access Container Product | >= 10.0, <= 10.0.9.1 | No fix yet |
| Verify Identity Access Product | >= 11.0, <= 11.0.2 | No fix yet |
| Verify Identity Access Container Product | >= 11.0, <= 11.0.2 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | IBM Langflow OSS: insecure direct object reference | High8.1 | No fix yet |
| Jul 17 | IBM Langflow OSS: hard-coded credentials | Critical9.8 | No fix yet |
| Jul 17 | IBM Langflow OSS: remote code execution | Critical9.8 | No fix yet |
| Jul 17 | IBM Langflow OSS: privilege escalation | Critical9.9 | No fix yet |
| Jul 17 | IBM Langflow OSS: improper input validation | Critical9.9 | No fix yet |
| Jul 17 | IBM Security Verify Access: information disclosure | Medium5.3 | No fix yet |