CVE-2026-12618

Summary

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.

Affected Software

VendorProductVersion RangeStatus
IBMSecurity Verify Access10.0 <= 10.0.9.2affected
IBMVerify Identity Access11.0 <= 11.0.3affected
IBMVerify Identity Access Container11.0 <= 11.0.3affected
IBMSecurity Verify Access Container10.0 <= 10.0.9.2affected

Weaknesses

  • CWE-74: CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References