CVE-2026-78401 CVE-2026-78406 CVE-2026-16823 CVE-2026-16916 CVE-2026-19491 CVE-2026-18740 CVE-2026-19482 CVE-2026-17189 CVE-2026-19494 CVE-2026-19493
IBM Verify Identity Access and Security Verify Access: critical deserialisation and authentication flaws
IBM's advisory covers critical flaws in Security Verify Access 10.0 through 10.0.9.2 and Verify Identity Access 11.0 through 11.0.3, including unauthenticated remote code execution and authentication bypass. Fixes are available; patch promptly.
What happened
IBM has published an advisory covering ten flaws in IBM Verify Identity Access and IBM Security Verify Access. The most severe are CVE-2026-78401 and CVE-2026-78406, both deserialisation of untrusted data flaws that can be exploited over the network by an unauthenticated attacker to execute arbitrary code. Each has a CVSS base score of 9.8. CVE-2026-16823 and CVE-2026-19491 are authentication bypass flaws with a score of 9.1, also reachable remotely without credentials.
The remaining flaws include CVE-2026-16916, a protection mechanism failure allowing a remote authenticated attacker with high privileges to execute arbitrary code; CVE-2026-18740 and CVE-2026-19482, command or argument injection flaws for low-privileged authenticated attackers, both scored 8.8; CVE-2026-19494, an authenticated authentication bypass scored 8.1; CVE-2026-19493, a path traversal allowing an unauthenticated remote attacker to write files, scored 7.5; and CVE-2026-17189, cross-site scripting in the Web UI scored 8.2 that could disclose credentials within a trusted session.
None of the flaws appears in CISA's KEV list, and IBM has not published exploitation statements. The CVE records do not indicate public disclosure or active exploitation.
Who is affected
Affected versions are IBM Security Verify Access 10.0 through 10.0.9.2, IBM Security Verify Access Container 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and IBM Verify Identity Access Container 11.0 through 11.0.3. Both traditional and container deployments are in scope. These products provide identity and access management, including authentication, single sign-on and web access control, so an internet-facing or authentication-path deployment should be treated as high priority.
What to do now
- Open IBM's advisory and confirm the fixed release for your branch. Specific fixed version numbers are not listed in IBM's advisory.
- Apply the update to every affected component: Security Verify Access 10.0 through 10.0.9.2, Verify Identity Access 11.0 through 11.0.3, and the corresponding container editions.
- If patching must wait, restrict access to the administration and web interfaces, particularly from the internet. IBM has not published a workaround in this advisory.
- After patching, review authentication policies and access logs for unexpected accounts, role changes or policy modifications, since the flaws include authentication bypass and code execution.
How to detect it
IBM's advisory does not list specific indicators of compromise. Start by confirming whether the Verify Identity Access or Security Verify Access web interface and management ports are reachable from untrusted networks, because several flaws are exploitable remotely without authentication. For internet-facing instances, review access logs for unexpected authentication events, new accounts or changes to access policy, which could indicate misuse of the authentication bypass or command execution flaws.
Beyond the patch
For an identity and access management platform, an authentication bypass or unauthenticated code execution flaw has an outsized blast radius: the system that verifies everyone can become the path into everything else. Because several of these flaws are reachable over the network without credentials, Virtual CISO Services (vCISO) can help identify exposed identity infrastructure and prioritise the patch. Implementation & Assessment Services uses penetration testing and hardening to find deserialisation and authentication flaws before they become advisories, and Managed Detection & Response provides the telemetry to catch credential abuse or code execution that a missed patch would otherwise hide.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-78401, CVE-2026-78406, CVE-2026-16823, CVE-2026-16916, CVE-2026-19491, CVE-2026-18740, CVE-2026-19482, CVE-2026-17189, CVE-2026-19494, CVE-2026-19493 Security Verify Access | 10.0 – ≤ 10.0.9.2 | No fixed version listed yet |
| CVE-2026-78401, CVE-2026-78406, CVE-2026-16823, CVE-2026-16916, CVE-2026-19491, CVE-2026-18740, CVE-2026-19482, CVE-2026-17189, CVE-2026-19494, CVE-2026-19493 Verify Identity Access | 11.0 – ≤ 11.0.3 | No fixed version listed yet |
| CVE-2026-78401, CVE-2026-78406, CVE-2026-16823, CVE-2026-16916, CVE-2026-19491, CVE-2026-18740, CVE-2026-19482, CVE-2026-17189, CVE-2026-19494, CVE-2026-19493 Security Verify Access Container | 10.0 – ≤ 10.0.9.2 | No fixed version listed yet |
| CVE-2026-78401, CVE-2026-78406, CVE-2026-16823, CVE-2026-16916, CVE-2026-19491, CVE-2026-18740, CVE-2026-19482, CVE-2026-17189, CVE-2026-19494, CVE-2026-19493 Verify Identity Access Container | 11.0 – ≤ 11.0.3 | No fixed version listed yet |
References
Vendor advisory
CVE
- CVE-2026-78401 — cve.org
- CVE-2026-78401 — NVD
- EUVD-2026-95270 — ENISA EUVD
- CVE-2026-78406 — Advisory →
- CVE-2026-78406 — cve.org
- CVE-2026-78406 — NVD
- EUVD-2026-95269 — ENISA EUVD
- CVE-2026-16823 — Advisory →
- CVE-2026-16823 — cve.org
- CVE-2026-16823 — NVD
- EUVD-2026-95282 — ENISA EUVD
- CVE-2026-16916 — Advisory →
- CVE-2026-16916 — cve.org
- CVE-2026-16916 — NVD
- EUVD-2026-95280 — ENISA EUVD
- CVE-2026-19491 — Advisory →
- CVE-2026-19491 — cve.org
- CVE-2026-19491 — NVD
- EUVD-2026-95277 — ENISA EUVD
- CVE-2026-18740 — cve.org
- CVE-2026-18740 — NVD
- EUVD-2026-95278 — ENISA EUVD
- CVE-2026-19482 — cve.org
- CVE-2026-19482 — NVD
- EUVD-2026-95273 — ENISA EUVD
- CVE-2026-17189 — cve.org
- CVE-2026-17189 — NVD
- EUVD-2026-95279 — ENISA EUVD
- CVE-2026-19494 — cve.org
- CVE-2026-19494 — NVD
- EUVD-2026-95276 — ENISA EUVD
- CVE-2026-19493 — cve.org
- CVE-2026-19493 — NVD
- EUVD-2026-95274 — ENISA EUVD