Junglewise Threat Intelligence

CVE-2026-8861: IBM Security Verify information disclosure via verbose error messages

CVE-2026-8861 · Severity: medium · CVSS 5.3 · Published 2026-07-17

Executive brief

IBM Security Verify, a solution used for managing user identities and access to applications, is vulnerable to information disclosure. An attacker can trigger specific errors that cause the system to display detailed technical messages in the web browser. This technical data could reveal internal system details that help an attacker plan more sophisticated follow-up attacks against the organization's security infrastructure.

Technical details

IBM Security Verify is vulnerable to CWE-209 (Generation of Error Message Containing Sensitive Information). The application fails to properly sanitize or suppress verbose technical error messages before they are sent to the client's browser. A remote, unauthenticated attacker can trigger these errors through standard network requests. The resulting messages may contain sensitive system metadata or configuration details that facilitate reconnaissance for further exploitation. IBM has addressed this in recent updates for both standard and containerized versions of Verify Identity Access and Security Verify Access.

Affected products

  • IBM Verify Identity Access 11.0.0 through 11.0.2
  • IBM Security Verify Access 10.0.0 through 10.0.9.1
  • IBM Verify Identity Access Container 11.0.0 through 11.0.2
  • IBM Security Verify Access Container 10.0.0 through 10.0.9.1

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References

Related threats