CVE-2026-78388: Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Security Verify Accessto a version that resolves this vulnerability.Fixed in 10.0.9.3 - Upgrade
Upgrade
IBM Verify Identity Accessto a version that resolves this vulnerability.Fixed in 11.0.3.1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3.
What does an attacker need to exploit this issue?
The attacker can act remotely without prior privileges, but exploitation requires user interaction. The attack relies on causing a user trusted by the website to transmit a malicious request.
What is the likely impact if exploitation succeeds?
An attacker could cause malicious or unauthorized actions to be performed in the context of a trusted user. The provided severity vector indicates integrity impact, with no stated confidentiality or availability impact.