Skip to content

CVE-2026-16916

IBM Security Verify Access protection mechanism failure allows remote code execution (CVE-2026-16916)

Critical 9.1 Vendor: IBM Published

IBM Security Verify Access 10.0–10.0.9.2 and Verify Identity Access 11.0–11.0.3 allow a remote authenticated attacker with high privileges to execute code remotely due to a protection mechanism failure. IBM indicates a fix is available; fixed versions are not listed in the CVE record.

What happened

IBM Security Verify Access and IBM Verify Identity Access contain a protection mechanism failure (CWE-693). A remote attacker who already holds a high-privilege account can exploit the flaw to execute arbitrary code. The vulnerability does not require user interaction and can be exploited over the network. It is rated critical, with CVSS 3.1 score 9.1; the scope change means a compromise can extend beyond the vulnerable component and affect other resources, with high impact to confidentiality, integrity and availability.

The CVE record does not indicate public disclosure or active exploitation, and there is no CISA KEV entry for this flaw. No vendor statement on exploitation is recorded.

Because this is an identity and access management product, it often sits in the direct path of authentication and access decisions. A successful exploit using a privileged account can undermine the controls the product is meant to enforce.

Who is affected

IBM lists four affected products: IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and the corresponding container editions — Security Verify Access Container 10.0 through 10.0.9.2 and Verify Identity Access Container 11.0 through 11.0.3. These are identity and access management products, used for authentication, single sign-on and access policy enforcement. If you run any of the listed versions, treat the deployment as affected until you confirm otherwise.

What to do now

  1. Confirm which IBM Security Verify Access or Verify Identity Access versions you run, including container editions. If you are within 10.0 through 10.0.9.2 or 11.0 through 11.0.3, treat the deployment as affected.
  2. Consult the IBM support page referenced on this page. A fix is marked as available, but the CVE record does not list specific fixed versions, so confirm the corrected release from IBM and apply it according to their guidance.
  3. Until the update is applied, review and restrict access to high-privilege accounts, since the attacker requires an authenticated high-privilege account. Limit network exposure to affected systems where possible.
  4. After updating, verify the installed version is outside the affected ranges and monitor for unusual activity.

How to detect it

Focus on the privileged account trail and the host: look for unusual processes or child processes spawned by the IBM access service, new administrative sessions, unexpected configuration changes, and successful high-privilege logins from unexpected IP ranges or outside normal hours. The CVE record does not provide specific indicators of compromise.

Beyond the patch

After patching, the wider question is whether an attacker was already able to use a privileged account against these identity services. When code execution or privileged access succeeds, the activity leaves a trail across endpoints and logs, which is what Managed Detection & Response (MDR) is designed to detect. The patch cycle also shows the importance of tracking suppliers: an IBM fix only closes the exposure once you know where IBM's products are deployed and how quickly the corrected release reaches your estate, which is a Supply Chain Defense & Third-Party Risk problem.

Affected and fixed versions

ProductAffectedFixed in
Security Verify Access10.0 – ≤ 10.0.9.2No fixed version listed yet
Verify Identity Access11.0 – ≤ 11.0.3No fixed version listed yet
Security Verify Access Container10.0 – ≤ 10.0.9.2No fixed version listed yet
Verify Identity Access Container11.0 – ≤ 11.0.3No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.