Format String Injection Vulnerability in IBM Security Verify Access and Verify Identity Access Products
CVE-2026-12004

8.7HIGH

What is CVE-2026-12004?

IBM Security Verify Access and related identity access products are susceptible to a format string injection vulnerability within their management interface. This flaw can be exploited by attackers through specially crafted HTTP requests, potentially leading to denial of service and exposing sensitive information.

Affected Version(s)

Security Verify Access 10.0 <= 10.0.9.2

Security Verify Access Container 10.0 <= 10.0.9.2

Verify Identity Access 11.0 <= 11.0.3

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.