Executive brief
IBM Verify Identity Access is a solution used to manage user identities and control access to corporate applications and data. A vulnerability in this software could allow a person who already has limited access to the system to gain full administrative (root) control. This could lead to unauthorized access to sensitive data, modification of security policies, or a complete takeover of the identity management infrastructure.
Technical details
The vulnerability (CWE-250) exists in IBM Verify Identity Access and IBM Security Verify Access (both standard and containerized versions). It is caused by certain components or processes executing with higher privileges than necessary. A locally authenticated attacker can exploit this misconfiguration to escalate their privileges to root. The vulnerability has a high impact on confidentiality, integrity, and availability, as it allows for a full system compromise. While the attack vector is local, the IBM-provided CVSS score of 9.3 reflects a critical severity due to the scope change and lack of required user interaction once local access is established.
Affected products
- IBM Verify Identity Access Container 11.0 through 11.0.2
- IBM Security Verify Access Container 10.0 through 10.0.9.1
- IBM Verify Identity Access 11.0 through 11.0.2
- IBM Security Verify Access 10.0 through 10.0.9.1
Timeline
- 2026-04-08: advisory: Initial publication of the vulnerability advisory by IBM.