Skip to content

CVE-2026-19491

IBM Verify Identity Access and Security Verify Access authentication bypass (CVE-2026-19491)

Critical 9.1 Vendor: IBM Published

IBM Security Verify Access 10.0 to 10.0.9.2 and Verify Identity Access 11.0 to 11.0.3 allow a remote unauthenticated attacker to bypass authentication. IBM has a fix available; restrict network exposure and apply it.

What happened

IBM has reported an improper authentication flaw in IBM Security Verify Access and IBM Verify Identity Access. An attacker who can reach a vulnerable instance over the network can bypass authentication without holding any credentials and without any action by a legitimate user. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, giving a score of 9.1 and high impact on confidentiality and integrity. In practice, successful exploitation could allow access to protected resources and modification of data behind the authentication boundary. IBM has not described the exact interface or post-bypass actions.

The CVE record does not list any public disclosure, and there is no statement from IBM or CISA that this flaw is being exploited. No KEV entry is associated with it.

Who is affected

These are the affected versions:

  • IBM Security Verify Access 10.0 through 10.0.9.2
  • IBM Verify Identity Access 11.0 through 11.0.3
  • IBM Security Verify Access Container 10.0 through 10.0.9.2
  • IBM Verify Identity Access Container 11.0 through 11.0.3

These products usually provide authentication, single sign-on and access policy enforcement for enterprise applications. Deployments exposed to the internet or to a broader corporate network should be checked first, because the flaw is reachable over the network without credentials.

What to do now

  1. Apply the IBM fix. IBM has marked a fix as available, but the CVE record does not list specific fixed build numbers; take the applicable version from IBM's support page.
  2. If you cannot patch immediately, restrict network access to IBM Verify Access and Identity Access services so that only trusted hosts and VPN segments can reach them. Network reachability is required for exploitation.
  3. Check public exposure, including load balancers, container orchestration and firewall rules, and remove any access from untrusted networks.
  4. Monitor authentication and access logs for unexpected successful logins while planning the update. No workaround has been published.

Beyond the patch

An authentication bypass in an identity enforcement point can quietly undermine the controls that protect multiple applications, not just one service. After patching, treat your Verify Access estate as critical exposure: Virtual CISO Services can help you identify and reduce publicly reachable authentication services, and Managed Detection & Response can monitor for the abnormal authenticated activity that follows a bypass. Patch first, then confirm your exposure posture.

Affected and fixed versions

ProductAffectedFixed in
Security Verify Access10.0 – ≤ 10.0.9.2No fixed version listed yet
Verify Identity Access11.0 – ≤ 11.0.3No fixed version listed yet
Security Verify Access Container10.0 – ≤ 10.0.9.2No fixed version listed yet
Verify Identity Access Container11.0 – ≤ 11.0.3No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.