Executive brief
IBM Verify Identity Access is an identity and access management platform used to control who can access corporate systems and applications. A vulnerability in the product allows an authenticated administrator to bypass authorization checks and execute commands that they are not entitled to perform, potentially compromising the integrity of access control policies and enabling privilege escalation within the identity management system.
Technical details
IBM Verify Identity Access contains an improper authorization vulnerability (CWE-285) due to inadequate validation of user-supplied input in command execution handlers. The vulnerability allows an authenticated administrator to bypass authorization checks and execute commands beyond their assigned privileges. The attack requires high-privilege credentials (PR:H) but network access, affecting confidentiality, integrity, and availability. An attacker with administrative credentials can leverage this flaw to escalate privileges and perform unauthorized operations within the identity management system. Patch availability from IBM should be checked via the security bulletin referenced.
Affected products
- IBM Verify Identity Access
Timeline
- 2026-09-15: disclosed