Junglewise Threat Intelligence

CVE-2026-5926: IBM Verify Identity Access use of weak cryptographic algorithms

CVE-2026-5926 · Severity: medium · CVSS 6.5 · Published 2026-04-23

Executive brief

IBM Verify Identity Access, a solution used for managing user identities and controlling access to corporate resources, is affected by a cryptographic vulnerability. The software uses outdated or weak encryption methods, which could allow an attacker with basic network access to decrypt and read highly sensitive information. This could lead to the exposure of credentials or other confidential data managed by the system.

Technical details

IBM Verify Identity Access (including Container versions) is vulnerable to the use of broken or risky cryptographic algorithms (CWE-327). The root cause is the implementation of weaker-than-expected encryption standards within the identity management suite. An authenticated attacker with network access can exploit this weakness to decrypt sensitive data transmitted or stored by the application. The vulnerability affects both the 10.x and 11.x release branches. IBM has released patches (v11.0.2 IF1 and v10.0.9.1 IF1) to address this issue by updating the cryptographic requirements.

Affected products

  • IBM Verify Identity Access Container 11.0 - 11.0.2
  • IBM Security Verify Access Container 10.0 - 10.0.9.1
  • IBM Verify Identity Access 11.0 - 11.0.2
  • IBM Security Verify Access 10.0 - 10.0.9.1

Timeline

  • 2026-04-14: disclosed: Initial publication by IBM
  • 2026-04-14: patched: Fixes released in v11.0.2 IF1 and v10.0.9.1 IF1
  • 2026-04-23: advisory: NVD publication date

References

Related threats