CVE-2026-11921
IBM · Verify Identity Access
IBM Verify Identity Access containers fail to correctly apply management password updates, potentially leaving systems vulnerable to unauthorized access via improperly secured credentials.
Executive summary
A critical vulnerability in IBM Verify Identity Access containers allows unauthenticated attackers to potentially bypass password change protections, posing a severe risk to credential security.
Vulnerability
This flaw involves insufficiently protected credentials (CWE-522) where management password change operations are not processed correctly. The vulnerability is exploitable by unauthenticated remote attackers with no user interaction required.
Business impact
The failure to correctly update management passwords can lead to the persistence of compromised or legacy credentials, granting unauthorized access to sensitive identity management infrastructure. Given the CVSS score of 9.1, this vulnerability presents a high risk of total impact to system integrity and confidentiality, potentially enabling broad unauthorized administrative control over the identity environment.
Remediation
Immediate Action: Update to the latest versions provided by IBM, specifically IBM Verify Identity Access v11.0.3 IF2 or IBM Security Verify Access v10.0.9.2 IF2.
Proactive Monitoring: Audit system logs for unexpected authentication events or attempts to access management interfaces that coincide with password change windows.
Compensating Controls: Restrict network access to management interfaces to trusted internal subnets or VPNs to limit the exposure of the vulnerable container endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant security oversight in the management of identity credentials. Organizations utilizing the affected versions of IBM Verify Identity Access must prioritize the application of the vendor-supplied patches immediately to ensure credential security and prevent potential unauthorized administrative access.
More IBM CVEs all →
History
CVE Brief tracked this CVE 3 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.1 (3.1)
- Analyst report written