Executive brief
IBM Verify Identity Access is an identity and access management system used to control administrative access and permissions within enterprise environments. A vulnerability in the system's command validation allows administrators to execute commands beyond their assigned permissions, potentially enabling unauthorized access to sensitive systems and data.
Technical details
This is an improper authorization vulnerability (CWE-285) in IBM Verify Identity Access caused by insufficient validation of user-supplied input during command execution. The vulnerability requires high-level privileges (administrator role) to exploit and is reachable over the network without user interaction. A malicious administrator can bypass command authorization checks to execute operations they are not entitled to perform, potentially gaining unauthorized access to system functionality and data. Patches addressing this issue have been made available by IBM.
Affected products
- IBM Verify Identity Access
Timeline
- 2026-09-15: disclosed