CVE-2026-17616: Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Other sources
Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Security Verify Accessto a version that resolves this vulnerability.Fixed in 10.0.9.2 IF2 - Upgrade
Upgrade
IBM Verify Identity Accessto a version that resolves this vulnerability.Fixed in 11.0.3 IF1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17616?
The severity of CVE-2026-17616 is medium with a score of 6.8.
What software versions are affected by CVE-2026-17616?
CVE-2026-17616 affects IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3.
How do I mitigate CVE-2026-17616?
To mitigate CVE-2026-17616, apply the latest updates from IBM for the affected software versions.
Is CVE-2026-17616 remotely exploitable?
Yes, CVE-2026-17616 has a vector that indicates it is remotely exploitable.
What type of impact does CVE-2026-17616 have?
CVE-2026-17616 can lead to potential exposure of sensitive user data due to weaker cryptographic validation.