CVE-2026-11934

Summary

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.

Affected Software

VendorProductVersion RangeStatus
IBMVerify Identity Access11.0.0 <= 11.0.3 Interim Fix 001affected
IBMSecurity Verify Access10.0.0 <= 10.0.9.2 Interim Fix 001affected
IBMVerify Identity Access Container11.0.0 <= 11.0.3 Interim Fix 001affected
IBMSecurity Verify Access Container10.0.0 <= 10.0.9.2 Interim Fix 001affected

Weaknesses

  • CWE-285: CWE-285 Improper Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References