Skip to content

CVE-2026-16823

IBM Security Verify Access and Verify Identity Access authentication bypass (CVE-2026-16823)

Critical 9.1 Vendor: IBM Published

IBM Security Verify Access 10.0 through 10.0.9.2 and Verify Identity Access 11.0 through 11.0.3 allow an unauthenticated remote attacker to bypass security restrictions due to improper authentication. CVSS 3.1 score is 9.1. A fix is available from IBM's support page.

What happened

The CVE record describes CVE-2026-16823 as improper authentication (CWE-287). An attacker can reach the affected product over the network, with no privileges and no interaction from a legitimate user. Successful exploitation lets the attacker bypass security restrictions; the CVSS vector shows high impact to confidentiality and integrity, with no impact to availability.

The CVSS 3.1 base score is 9.1, critical. The CVE record does not state that exploitation has occurred in the wild, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalogue. The lack of required credentials or user interaction makes this urgent for organisations that expose the product to untrusted networks.

Who is affected

The affected products are IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and the corresponding container editions: IBM Security Verify Access Container 10.0 through 10.0.9.2 and IBM Verify Identity Access Container 11.0 through 11.0.3. These products provide authentication, federation, and access policy enforcement for applications, so they are typically network-facing and may be reachable from untrusted networks.

What to do now

  1. Confirm the fixed build for your product line on IBM's support page. A fix is available, but specific fixed version numbers are not listed in the CVE record, so use IBM's page to identify the correct version for Security Verify Access or Verify Identity Access.
  2. Apply the fix as a priority, given the critical CVSS 3.1 score of 9.1 and the lack of required credentials.
  3. If you cannot patch immediately, restrict network access to affected appliances and containers from untrusted networks, and review access events for unexpected behaviour.
  4. Check both the non-container and container editions in your estate, since both are affected.

Beyond the patch

Identity and access management sits in front of other systems, so an authentication bypass here can undermine more than the appliance itself. After patching, check whether the product is reachable from networks that do not need it; that kind of exposure review is part of Virtual CISO Services (vCISO). A penetration test or hardening engagement from Implementation & Assessment Services can also test the authentication and federation controls that this class of flaw targets, before an attacker does.

Affected and fixed versions

ProductAffectedFixed in
Security Verify Access10.0 – ≤ 10.0.9.2No fixed version listed yet
Verify Identity Access11.0 – ≤ 11.0.3No fixed version listed yet
Security Verify Access Container10.0 – ≤ 10.0.9.2No fixed version listed yet
Verify Identity Access Container11.0 – ≤ 11.0.3No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.