CVE-2026-11929
moderateWeak Cryptographic Validation in IBM Security Verify Identity Access Reverse Proxy
The Reverse Proxy component of IBM Security Verify Identity Access, when deployed in certain configurations, performs weaker-than-expected cryptographic validation of user-supplied data (CWE-327). Because the flaw is remotely exploitable over the network with no authentication, privileges, or user interaction required (AV:N/AC:L/PR:N/UI:N), an attacker who can reach the proxy may be able to decrypt, forge, or otherwise infer sensitive data such as session tokens or credentials handled by the proxy. The impact is limited to confidentiality (C:H/I:N/A:N), rated CVSS 3.1 7.5 (high) — attackers gain information disclosure rather than code execution or service disruption. Organizations running the SVI Reverse Proxy in an affected configuration, typically enterprises exposing web SSO and authentication endpoints to the internet, are at risk. There is no known public proof of concept and no confirmed exploitation in the wild as of this writing.
What to do: Apply IBM's fixed versions or interim fixes per the official security bulletin, confirming affected version ranges with IBM support since the advisory does not enumerate them. Audit reverse proxy cryptographic settings — disable deprecated ciphers/algorithms on SSL profiles and junctions, enforce TLS 1.2+, and ensure strong validation of user-supplied cryptographic material. Review reverse proxy and audit logs for repeated malformed or anomalous client requests that could indicate probing of the weak validation path.
| IBM Security Verify Identity Access Reverse Proxy (reverse proxy component of IBM's enterprise identity and access managemen | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
- Weakness
- CWE-327
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.