CVE-2026-11934: Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Security Verify Accessto a version that resolves this vulnerability.Fixed in v10.0.9.2 IF2 - Upgrade
Upgrade
IBM Verify Identity Accessto a version that resolves this vulnerability.Fixed in v11.0.3 IF2
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an administrator of IBM Verify Identity Access. The available information does not indicate that unauthenticated or ordinary users can exploit it.
What is the likely impact of successful exploitation?
A vulnerable administrator could execute additional commands beyond those they are entitled to run. The available information does not specify which commands, affected versions, or configuration conditions.