Junglewise Threat Intelligence

CVE-2026-11904: IBM Verify Identity Access information disclosure in error messages

CVE-2026-11904 · Severity: medium · CVSS 5.3 · Published 2026-07-30

Executive brief

IBM Verify Identity Access is a solution used to manage user identities and control access to corporate applications. A vulnerability in this system could allow an unauthorized person to view detailed technical error messages through their web browser. These messages may contain sensitive internal information that could help an attacker plan more sophisticated attacks against the organization's infrastructure.

Technical details

The vulnerability is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). It affects the web-based interface of IBM Verify Identity Access and Security Verify Access across both traditional and containerized deployments. A remote, unauthenticated attacker can trigger conditions that cause the application to return verbose technical error messages to the browser. These messages may leak sensitive system details or configuration information. This information disclosure can be leveraged as a reconnaissance step for further exploitation of the target system. IBM has addressed these vulnerabilities in the referenced security bulletin.

Affected products

  • IBM Verify Identity Access 11.0 through 11.0.2
  • IBM Security Verify Access 10.0 through 10.0.9.1
  • IBM Verify Identity Access Container 11.0 through 11.0.2
  • IBM Security Verify Access Container 10.0 through 10.0.9.1

Timeline

  • 2026-07-30: disclosed
  • 2026-07-30: advisory

References

Related threats