CVE-2026-12005: Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
Other sources
IBM Verify Identity Access contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12005?
The severity of CVE-2026-12005 is high, rated at 7.2.
What are the affected products for CVE-2026-12005?
CVE-2026-12005 affects IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3.
How do I fix CVE-2026-12005?
To fix CVE-2026-12005, update to the latest patched versions of the affected IBM products.
What type of vulnerability is CVE-2026-12005?
CVE-2026-12005 is an input validation vulnerability that can lead to OS command injection.
Who is impacted by CVE-2026-12005?
CVE-2026-12005 can impact already privileged attackers utilizing the management interface of the affected IBM products.