CVE-2026-16823: Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Security Verify Accessto a version that resolves this vulnerability.Fixed in 10.0.9.3 - Upgrade
Upgrade
IBM Verify Identity Accessto a version that resolves this vulnerability.Fixed in 11.0.3.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3.
Does exploitation require an authenticated account or user interaction?
No. The published vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the likely impact if exploited?
The issue could allow a remote attacker to bypass security restrictions because of improper authentication. The severity vector indicates high confidentiality and integrity impact, with no availability impact stated.