CVE-2026-78406
IBM Security Verify Access and Verify Identity Access deserialization flaw allows unauthenticated remote code execution (CVE-2026-78406)
Unauthenticated RCE in IBM Security Verify Access 10.0–10.0.9.2 and IBM Verify Identity Access 11.0–11.0.3, including containers. Deserialization of untrusted data; CVSS 9.8 critical. Apply IBM's fix; no fixed version listed in the CVE record.
What happened
IBM Security Verify Access and IBM Verify Identity Access contain a deserialization-of-untrusted-data flaw. An attacker who can reach an affected service over the network can send crafted data that the application deserializes, leading to arbitrary code execution on the system. The CVSS v3.1 rating is 9.8 critical: the attack is reachable over the network, has low attack complexity, requires no privileges and no user interaction, and results in high impact to confidentiality, integrity and availability. IBM has not stated that this flaw has been exploited; the CVE record does not report exploitation.
Who is affected
These products and versions are affected, as listed in the CVE record:
- IBM Security Verify Access 10.0 through 10.0.9.2
- IBM Verify Identity Access 11.0 through 11.0.3
- IBM Security Verify Access Container 10.0 through 10.0.9.2
- IBM Verify Identity Access Container 11.0 through 11.0.3
These are identity and access management appliances or containers, often used in authentication pathways and may be reachable from untrusted networks. If you run any of the above, treat the deployment as in scope.
What to do now
- Apply IBM's fix. The CVE record marks a fix as available but does not list fixed version numbers. Confirm the exact patched release for your version from IBM support page.
- If patching must be delayed, restrict network access to the affected systems until the update is applied, especially any interfaces reachable from untrusted networks.
- After patching, verify that the product is no longer at a vulnerable version and that authentication still works normally.
No workaround has been published.
How to detect it
No vendor-specific indicators of compromise are listed in the CVE record. Because a successful attack would execute code on the affected system, monitor the affected identity appliances for unexpected process execution, unusual outbound connections, or changes to authentication-related accounts. EDR and SIEM coverage is most likely to surface this activity.
Beyond the patch
An unauthenticated remote code execution flaw in an identity product is both an exposure problem and a detection problem. If the affected service is reachable from the internet, Virtual CISO Services (vCISO) can help map and reduce that exposure. Because exploitation would run code on the identity system itself, Managed Detection & Response (MDR) should be watching for the resulting activity. After patching, Implementation & Assessment Services can test the deployment's deserialisation and authentication controls.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Security Verify Access | 10.0 – ≤ 10.0.9.2 | No fixed version listed yet |
| Verify Identity Access | 11.0 – ≤ 11.0.3 | No fixed version listed yet |
| Security Verify Access Container | 10.0 – ≤ 10.0.9.2 | No fixed version listed yet |
| Verify Identity Access Container | 11.0 – ≤ 11.0.3 | No fixed version listed yet |