Junglewise Threat Intelligence

CVE-2026-12358: IBM Verify Identity Access denial of service due to uncontrolled recursion

CVE-2026-12358 · Severity: high · CVSS 7.5 · Published 2026-09-15

Executive brief

IBM Verify Identity Access is an identity and access management solution used to control authentication and authorization for enterprise applications. A remote attacker without credentials can send specially crafted requests that trigger uncontrolled recursion in the system, causing it to crash and become unavailable to legitimate users. This results in service outages affecting business operations and user access to protected resources.

Technical details

The vulnerability is a CWE-674 uncontrolled recursion flaw in IBM Verify Identity Access caused by insufficient validation of incoming request resources. An unauthenticated network attacker can exploit this by sending malformed or specially crafted requests that bypass validation controls and trigger recursive processing, exhausting system resources and crashing the service. The attack requires no special preconditions or user interaction. IBM has released patches to address this vulnerability as documented in their security bulletin.

Affected products

  • IBM Verify Identity Access

Timeline

  • 2026-09-15: disclosed

References

Related threats