Skip to content
Saturday, October 10, 2026AboutContactRSS
IBM Verify Identity Access 11.0.3 Users at Risk From Critical Deserialization Flaw
Vulnerabilities

IBM Verify Identity Access 11.0.3 Users at Risk From Critical Deserialization Flaw

A severe vulnerability in IBM Security Verify Access allows remote attackers to run arbitrary code without credentials.

Key points

  • IBM Security Verify Access versions 10.0 through 10.0.9.2 are affected.
  • IBM Verify Identity Access versions 11.0 through 11.0.3 are also vulnerable.
  • The flaw stems from insecure deserialization of untrusted data.
  • The National Vulnerability Database rates the severity as Critical with a CVSS score of 9.8.

IBM has disclosed a critical remote code execution vulnerability in its Security Verify Access and Verify Identity Access products. The flaw allows unauthenticated attackers to execute arbitrary code on affected systems by exploiting insecure data deserialization.

What happened

The National Vulnerability Database has published details for CVE-2026-78401, identifying a high-severity weakness in IBM’s identity management infrastructure. According to the NVD record, the vulnerability exists in IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3. The issue also impacts the containerized versions of these products, specifically IBM Security Verify Access Container up to 10.0.9.2 and IBM Verify Identity Access Container up to 11.0.3.

The root cause is classified under CWE-502, which relates to deserialization of untrusted data. This weakness permits a remote attacker to send specially crafted data that the application processes without proper validation. Because the attacker does not need authentication to exploit this flaw, the barrier to entry is effectively non-existent for anyone with network access to the vulnerable service. The NVD assigns a CVSS score of 9.8, categorizing the threat as Critical. This score reflects the ease of exploitation and the severe impact on system integrity, availability, and confidentiality.

Why it matters

For CISOs and IT managers, this vulnerability represents an immediate and severe risk to organizational security perimeters. IBM Security Verify Access is widely deployed as a gateway for identity and access management, often sitting at the edge of enterprise networks. A compromise here can serve as a beachhead for lateral movement within the internal network.

The unauthenticated nature of the exploit means that automated scanning tools or opportunistic threat actors can target these systems without prior reconnaissance or credential theft. Once arbitrary code is executed, attackers can potentially install malware, steal sensitive data, or disrupt business operations. The inclusion of containerized versions in the affected scope expands the risk surface to organizations using modern, cloud-native deployment models. Until a patch is confirmed and deployed, any instance running the listed versions remains exposed to full system takeover.

What to watch

  • Monitor IBM’s security advisories for official patch releases.
  • Review network logs for unusual outbound traffic from identity gateways.
  • Check for unexpected process executions or new user accounts on affected servers.
  • Verify that all instances are running versions prior to the fixed release.

What to do and how to stay safe: IBM

  • Inventory all deployments of IBM Security Verify Access and IBM Verify Identity Access to identify affected versions.
  • Restrict network access to these services using firewalls or access control lists to limit exposure to untrusted networks.
  • Enable detailed logging on identity gateways to detect potential exploitation attempts.
  • Prepare to apply updates immediately once the vendor provides a confirmed fix.

General security guidance from the Patch Gazette newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Which specific IBM products are affected by CVE-2026-78401?

IBM Security Verify Access (10.0-10.0.9.2), IBM Verify Identity Access (11.0-11.0.3), and their respective container versions are affected.

Is authentication required to exploit this vulnerability?

No, the NVD record states that a remote unauthenticated attacker can exploit this flaw to execute arbitrary code.

What is the severity rating of this vulnerability?

The National Vulnerability Database rates CVE-2026-78401 as Critical with a CVSS score of 9.8.

Sources

  1. CVE Program
  2. NVD
IBMCVE-2026-78401Security Verify AccessVerify Identity AccessRemote Code Execution

Related stories