CVE-2026-12358
moderateUncontrolled Recursion Denial of Service in IBM Verify Identity Access
IBM Verify Identity Access contains a denial-of-service vulnerability classified as CWE-674 (uncontrolled recursion), caused by insufficient validation of resources in incoming requests. A remote, unauthenticated attacker can send specially crafted requests that trigger excessive recursion, exhausting CPU, memory, or stack resources and causing the identity service to hang or crash. Because this is an access-management product typically placed at the network edge to authenticate users, a successful attack makes login and single sign-on services unavailable to an entire organization. Affected parties are enterprises running IBM Verify Identity Access (including appliances and containerized deployments). No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is currently theoretical.
What to do: Patch to the fixed releases listed in IBM's security bulletin for this CVE as soon as it is available, prioritizing any appliance or runtime instance that is internet-facing. Until patched, place a WAF or reverse proxy in front of the service to rate-limit and reject abnormally large, deeply nested, or rapidly repeated requests, and alert on sustained request floods or unexplained CPU/memory spikes on Verify Identity Access nodes. Verify service health and automatic restart/recovery after any suspected resource-exhaustion event.
| IBM Verify Identity Access | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
- Weakness
- CWE-674
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.