Junglewise Threat Intelligence

CVE-2026-17616: IBM Security Verify Access cryptographic validation weakness

CVE-2026-17616 · Severity: medium · CVSS 6.8 · Published 2026-08-12

Technologies: IBM Verify Identity Access, IBM Verify Identity Access Container, IBM Security Verify Access. Vendors: IBM.

Executive brief

IBM Security Verify Access and IBM Verify Identity Access are authentication and identity management solutions deployed in enterprise environments to control user access and manage identity credentials. The reverse proxy component in certain configurations fails to properly validate cryptographic signatures on user-supplied data, potentially allowing attackers to forge or tamper with authentication tokens. This could lead to unauthorized access to protected applications and sensitive data.

Technical details

This vulnerability is a cryptographic validation weakness (CWE-310) in the reverse proxy component of IBM's identity and access management platform. The vulnerability affects the cryptographic validation of user-supplied data in specific configurations, allowing attackers to bypass or weaken the integrity checks on authentication-related data. An attacker with low privileges (PR:L) can exploit this over the network (AV:N) through non-standard conditions (AC:H) to gain unauthorized access to confidential information and modify data (C:H, I:H). The vulnerability requires authentication credentials to exploit. Patches have been released by IBM for affected versions.

Affected products

  • IBM Security Verify Access 10.0 through 10.0.9.2
  • IBM Verify Identity Access 11.0 through 11.0.3
  • IBM Verify Identity Access Container 11.0 through 11.0.3

Timeline

  • 2026-08-12: disclosed

References

Related threats