Executive brief
IBM Verify Identity Access is an identity and access management platform used to control user authentication and authorization across enterprise systems. A vulnerability in how the platform applies password change operations in containerized deployments may fail to properly protect management credentials, potentially allowing unauthorized access to administrative functions or exposure of sensitive authentication data.
Technical details
CVE-2026-11921 is an insufficiently protected credentials vulnerability (CWE-522) in IBM Verify Identity Access containers. The root cause is improper handling of management password change operations, which may not be correctly applied in containerized environments. This is a local attack vector requiring high privilege level (administrator) with high attack complexity, resulting in integrity loss and potential availability impact. The vulnerability was published on 2026-09-15 and there is no public evidence of active exploitation.
Affected products
- IBM Verify Identity Access
Timeline
- 2026-09-15: disclosed