CVE-2026-11934
moderateAdmin Privilege Escalation via Improper Authorization in IBM Verify Identity Access
IBM Verify Identity Access improperly validates user-supplied input, resulting in an improper authorization flaw (CWE-285) that allows an authenticated administrator to execute additional commands they are not entitled to run. The flaw is triggered remotely by an administrator submitting crafted input to administrative functions, requiring no victim interaction. A successful attacker gains execution of unauthorized commands on the identity and access management platform, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2, network vector, high privileges required). Any organization running an affected IBM Verify Identity Access deployment with privileged administrative accounts is exposed, though the high-privilege prerequisite limits this to attacker-controlled or compromised admin accounts. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and no exploitation has been reported to date.
What to do: Apply IBM's fixed releases as soon as they are published in the vendor's security bulletin for CVE-2026-11934, since affected and patched versions are enumerated there. In the interim, restrict administrative interface access to trusted management networks or VPN, enforce least-privilege role assignment so admins hold only the entitlements they need, and audit administrative command-execution logs for unexpected or out-of-scope commands indicative of abuse.
| IBM Verify Identity Access | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.
- Weakness
- CWE-285
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.