CVE-2026-11926
moderateUnauthenticated Denial of Service in IBM Verify Identity Access
IBM Verify Identity Access contains a denial-of-service vulnerability caused by insufficient validation of incoming request resources (CWE-400, uncontrolled resource consumption). A remote, unauthenticated attacker can trigger the flaw by sending specially crafted requests that cause the service to exhaust memory, CPU, or other resources, making the identity platform unavailable to legitimate users. With a CVSS 3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), the flaw is trivially reachable over the network with no credentials or user interaction required. Because Verify Identity Access typically fronts authentication and single sign-on for enterprise applications, an outage can lock users out of all downstream services. There is no evidence of exploitation in the wild: the CVE is not in the CISA KEV catalog and no public proof-of-concept is known.
What to do: Apply the fix described in IBM's security bulletin for CVE-2026-11926 as soon as patched builds are available, prioritizing any appliance or container instance that is internet-facing for SSO. In the interim, place the Verify Identity Access runtime endpoints behind a reverse proxy or WAF with request rate-limiting and payload-size constraints to blunt resource-exhaustion attempts, and monitor appliance memory/CPU and authentication service availability for signs of abuse. Verify that virtual host and federation endpoints are not exposed more broadly than required.
| IBM Verify Identity Access | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.