Executive brief
IBM Verify Identity Access is an identity and access management system used to authenticate users and control access to enterprise applications. A remote attacker can crash or hang the service by sending specially crafted requests that exploit insufficient input validation, causing service outages and blocking legitimate users from accessing protected resources.
Technical details
This vulnerability (CVE-2026-12358) is caused by uncontrolled recursion (CWE-674) resulting from insufficient validation of incoming request resources. The vulnerability is remotely exploitable over the network without requiring authentication or user interaction. An unauthenticated attacker can trigger resource exhaustion by sending malformed requests, causing the application to enter an infinite or deeply nested recursion loop that consumes memory and CPU until the service becomes unavailable. The attack requires only network access and no special preconditions. Patch availability should be verified through IBM's security bulletin.
Affected products
- IBM Verify Identity Access
Timeline
- 2026-09-15: disclosed