Junglewise Threat Intelligence

CVE-2026-11927: IBM Security Verify Identity Access parameter injection in reverse proxy

CVE-2026-11927 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

IBM Security Verify Identity Access is an identity and access management (IAM) solution that acts as a reverse proxy to control and authenticate requests to protected services. A vulnerability allows attackers to inject malicious parameters into requests forwarded to third-party services, potentially bypassing security controls or manipulating the behavior of downstream applications without authentication.

Technical details

This vulnerability is an improper neutralization of special elements in output used by a downstream component (CWE-74, injection class). The IBM Security Verify Identity Access reverse proxy fails to properly sanitize or validate parameters before forwarding requests to backend services. An attacker with network access can inject arbitrary parameters into requests, allowing manipulation of third-party service calls. The attack requires only network access with no authentication or user interaction; however, the attack complexity is rated high (AC:H). Successful exploitation can lead to information disclosure and integrity violations against downstream systems.

Affected products

  • IBM Security Verify Identity Access

Timeline

  • 2026-09-15: disclosed

References

Related threats