Junglewise Threat Intelligence

CVE-2026-1342: IBM Verify Identity Access local script execution

CVE-2026-1342 · Severity: high · CVSS 8.5 · Published 2026-04-08

Technologies: IBM Security Verify Access Container, IBM Verify Identity Access, IBM Verify Identity Access Container, IBM Security Verify Access. Vendors: IBM.

Executive brief

IBM Verify Identity Access, a solution used for managing user identities and controlling access to corporate resources, is vulnerable to a security flaw that allows local users to run unauthorized scripts. An attacker with local access to the system could bypass security boundaries to execute malicious code, potentially leading to data theft or unauthorized system changes. This impacts the integrity of the identity management platform and the security of the environments it protects.

Technical details

The vulnerability is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere). It affects both the containerized and traditional deployments of IBM Verify Identity Access and Security Verify Access. A locally authenticated attacker can exploit this flaw to execute malicious scripts that originate from outside the application's intended control boundaries. Because the vulnerability carries a 'Changed' Scope (S:C) in its CVSS vector, the execution may allow the attacker to impact components beyond the immediate security scope of the application. The attack requires local access but, according to the vendor's CVSS string, may not require specific privileges (PR:N) to achieve high confidentiality impact.

Affected products

  • IBM Verify Identity Access Container 11.0 - 11.0.2
  • IBM Security Verify Access Container 10.0 - 10.0.9.1
  • IBM Verify Identity Access 11.0 - 11.0.2
  • IBM Security Verify Access 10.0 - 10.0.9.1

Timeline

  • 2026-04-07: disclosed
  • 2026-04-08: advisory

References

Related threats