Weak Cryptographic Validation in IBM Security Verify Access Products
CVE-2026-11923

7.4HIGH

What is CVE-2026-11923?

A vulnerability has been identified in IBM Security Verify Access and related products where the Reverse Proxy, under specific configurations, may perform suboptimal cryptographic validation of user-supplied data. This can potentially expose the application to security risks, encouraging unauthorized access or data manipulation. Organizations using these versions should take immediate steps to review their configurations and apply the necessary patches to enhance their data protection measures.

Affected Version(s)

Security Verify Access 10.0 <= 10.0.9.2

Security Verify Access Container 10.0 <= 10.0.9.2

Verify Identity Access 11.0 <= 11.0.3

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.