Junglewise Threat Intelligence

CVE-2026-4938: IBM Verify Identity Access incorrect authorization for read-only users

CVE-2026-4938 · Severity: medium · CVSS 6.5 · Published 2026-07-17

Executive brief

IBM Verify Identity Access is a solution used to manage user identities and control access to corporate applications. A security flaw in this product allows a user who should only have 'read-only' view access to bypass these restrictions and make unauthorized changes or deployments. This could lead to unauthorized configuration changes that compromise the integrity of the access management system.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in IBM Verify Identity Access and IBM Security Verify Access (including containerized versions). The flaw allows a remote authenticated attacker with low-level 'read-only' privileges to bypass intended access controls. By exploiting this vulnerability, the attacker can perform unauthorized modifications and deployments that should be restricted to higher-privileged administrative accounts. The vulnerability is reachable over the network without user interaction, provided the attacker has valid credentials for a read-only account. IBM has addressed this in a security bulletin, and users should update to the latest patched versions.

Affected products

  • IBM Verify Identity Access 11.0 through 11.0.2
  • IBM Security Verify Access 10.0 through 10.0.9.1
  • IBM Verify Identity Access Container 11.0 through 11.0.2
  • IBM Security Verify Access Container 10.0 through 10.0.9.1

Timeline

  • 2026-07-17: disclosed: Initial publication of the CVE record and IBM advisory.

References

Related threats