Junglewise Threat Intelligence

CVE-2026-1346: IBM Verify Identity Access privilege escalation to root

CVE-2026-1346 · Severity: critical · CVSS 9.3 · Published 2026-04-08

Executive brief

IBM Verify Identity Access is a solution used to manage user identities and control access to corporate applications and data. A vulnerability in this software could allow a person who already has limited access to the system to gain full administrative (root) control. This could lead to unauthorized access to sensitive data, modification of security policies, or a complete takeover of the identity management infrastructure.

Technical details

The vulnerability (CWE-250) exists in IBM Verify Identity Access and IBM Security Verify Access (both standard and containerized versions). It is caused by certain components or processes executing with higher privileges than necessary. A locally authenticated attacker can exploit this misconfiguration to escalate their privileges to root. The vulnerability has a high impact on confidentiality, integrity, and availability, as it allows for a full system compromise. While the attack vector is local, the IBM-provided CVSS score of 9.3 reflects a critical severity due to the scope change and lack of required user interaction once local access is established.

Affected products

  • IBM Verify Identity Access Container 11.0 through 11.0.2
  • IBM Security Verify Access Container 10.0 through 10.0.9.1
  • IBM Verify Identity Access 11.0 through 11.0.2
  • IBM Security Verify Access 10.0 through 10.0.9.1

Timeline

  • 2026-04-08: advisory: Initial publication of the vulnerability advisory by IBM.

References

Related threats