CVE-2026-19491
IBM Verify Identity Access and Security Verify Access authentication bypass (CVE-2026-19491)
IBM Security Verify Access 10.0 to 10.0.9.2 and Verify Identity Access 11.0 to 11.0.3 allow a remote unauthenticated attacker to bypass authentication. IBM has a fix available; restrict network exposure and apply it.
What happened
IBM has reported an improper authentication flaw in IBM Security Verify Access and IBM Verify Identity Access. An attacker who can reach a vulnerable instance over the network can bypass authentication without holding any credentials and without any action by a legitimate user. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, giving a score of 9.1 and high impact on confidentiality and integrity. In practice, successful exploitation could allow access to protected resources and modification of data behind the authentication boundary. IBM has not described the exact interface or post-bypass actions.
The CVE record does not list any public disclosure, and there is no statement from IBM or CISA that this flaw is being exploited. No KEV entry is associated with it.
Who is affected
These are the affected versions:
- IBM Security Verify Access 10.0 through 10.0.9.2
- IBM Verify Identity Access 11.0 through 11.0.3
- IBM Security Verify Access Container 10.0 through 10.0.9.2
- IBM Verify Identity Access Container 11.0 through 11.0.3
These products usually provide authentication, single sign-on and access policy enforcement for enterprise applications. Deployments exposed to the internet or to a broader corporate network should be checked first, because the flaw is reachable over the network without credentials.
What to do now
- Apply the IBM fix. IBM has marked a fix as available, but the CVE record does not list specific fixed build numbers; take the applicable version from IBM's support page.
- If you cannot patch immediately, restrict network access to IBM Verify Access and Identity Access services so that only trusted hosts and VPN segments can reach them. Network reachability is required for exploitation.
- Check public exposure, including load balancers, container orchestration and firewall rules, and remove any access from untrusted networks.
- Monitor authentication and access logs for unexpected successful logins while planning the update. No workaround has been published.
Beyond the patch
An authentication bypass in an identity enforcement point can quietly undermine the controls that protect multiple applications, not just one service. After patching, treat your Verify Access estate as critical exposure: Virtual CISO Services can help you identify and reduce publicly reachable authentication services, and Managed Detection & Response can monitor for the abnormal authenticated activity that follows a bypass. Patch first, then confirm your exposure posture.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Security Verify Access | 10.0 – ≤ 10.0.9.2 | No fixed version listed yet |
| Verify Identity Access | 11.0 – ≤ 11.0.3 | No fixed version listed yet |
| Security Verify Access Container | 10.0 – ≤ 10.0.9.2 | No fixed version listed yet |
| Verify Identity Access Container | 11.0 – ≤ 11.0.3 | No fixed version listed yet |