ZeroHour

CVE-2026-12358

moderate

Uncontrolled Recursion Denial of Service in IBM Verify Identity Access

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

IBM Verify Identity Access contains a denial-of-service vulnerability classified as CWE-674 (uncontrolled recursion), caused by insufficient validation of resources in incoming requests. A remote, unauthenticated attacker can send specially crafted requests that trigger excessive recursion, exhausting CPU, memory, or stack resources and causing the identity service to hang or crash. Because this is an access-management product typically placed at the network edge to authenticate users, a successful attack makes login and single sign-on services unavailable to an entire organization. Affected parties are enterprises running IBM Verify Identity Access (including appliances and containerized deployments). No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation is currently theoretical.

What to do: Patch to the fixed releases listed in IBM's security bulletin for this CVE as soon as it is available, prioritizing any appliance or runtime instance that is internet-facing. Until patched, place a WAF or reverse proxy in front of the service to rate-limit and reject abnormally large, deeply nested, or rapidly repeated requests, and alert on sustained request floods or unexplained CPU/memory spikes on Verify Identity Access nodes. Verify service health and automatic restart/recovery after any suspected resource-exhaustion event.

Affected
IBM Verify Identity Access
Estimated exposure
moderate≈ low thousands of internet-exposed deployments (order of 1k–10k appliances/instances), plus a larger unknown number of internal-only installations — Verify Identity Access is an enterprise IAM product deployed by a subset of large organizations, and public internet scans (Shodan/Censys-style fingerprinting of IBM ISAM/Verify Access appliances) historically show on the order of a few…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

Weakness
CWE-674
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.