ZeroHour

CVE-2026-11934

moderate

Admin Privilege Escalation via Improper Authorization in IBM Verify Identity Access

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

IBM Verify Identity Access improperly validates user-supplied input, resulting in an improper authorization flaw (CWE-285) that allows an authenticated administrator to execute additional commands they are not entitled to run. The flaw is triggered remotely by an administrator submitting crafted input to administrative functions, requiring no victim interaction. A successful attacker gains execution of unauthorized commands on the identity and access management platform, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2, network vector, high privileges required). Any organization running an affected IBM Verify Identity Access deployment with privileged administrative accounts is exposed, though the high-privilege prerequisite limits this to attacker-controlled or compromised admin accounts. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no exploitation has been reported to date.

What to do: Apply IBM's fixed releases as soon as they are published in the vendor's security bulletin for CVE-2026-11934, since affected and patched versions are enumerated there. In the interim, restrict administrative interface access to trusted management networks or VPN, enforce least-privilege role assignment so admins hold only the entitlements they need, and audit administrative command-execution logs for unexpected or out-of-scope commands indicative of abuse.

Affected
IBM Verify Identity Access
Estimated exposure
moderate≈1,000–10,000 enterprise deployments worldwide (order of magnitude: low thousands of organizations) — IBM Verify Identity Access (formerly IBM Security Access Manager) is an enterprise IAM appliance/software typically deployed in small numbers per organization, with internet scans historically surfacing only low thousands of related IBM…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.

Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.