CVE-2026-12101: Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
Published Sep 15, 2026
·Updated
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Security Verify Accessto a version that resolves this vulnerability.Fixed in v10.0.9.2 IF2 - Upgrade
Upgrade
IBM Verify Identity Accessto a version that resolves this vulnerability.Fixed in v11.0.3 IF2
Event History
Sep 15, 2026
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue requires administrator access. An affected administrator can execute additional commands beyond those they are entitled to run.
2
What is the security impact?
Improper validation of user-supplied requests can allow an administrator to bypass intended command authorization boundaries and execute additional commands.