CVE-2026-1342
8.5IBM · Verify Identity Access / Security Verify Access
IBM Verify Identity Access and Security Verify Access are susceptible to an inclusion of functionality from an untrusted control sphere, allowing locally authenticated users to execute malicious scripts.
Executive summary
A vulnerability in IBM Verify Identity Access and Security Verify Access products could allow a locally authenticated user to execute malicious scripts, posing a risk to system integrity.
Vulnerability
The software is vulnerable to the inclusion of functionality from an untrusted control sphere (CWE-829), which permits a locally authenticated user to trigger the execution of unauthorized scripts outside of the intended control sphere.
Business impact
The exploitation of this vulnerability could lead to unauthorized script execution, potentially compromising the integrity of the identity management environment. With a CVSS score of 8.5, this high-severity flaw carries significant risk, as it may allow an attacker to escalate privileges or manipulate security functions within the identity access infrastructure, ultimately leading to unauthorized administrative actions or data exposure.
Remediation
Immediate Action: Update to the latest versions: IBM Verify Identity Access v11.0.2 IF1 or IBM Security Verify Access v10.0.9.1 IF1 via the IBM Fix Central portal.
Proactive Monitoring: Review system and audit logs for unusual script execution patterns or unauthorized modifications to configuration files that could indicate attempted exploitation.
Compensating Controls: Restrict local access to the underlying operating system or container environment to only highly trusted administrative personnel to mitigate the risk posed by locally authenticated users.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical role of identity management platforms in enterprise security, organizations should prioritize the deployment of the provided security updates. Administrators must apply the version-specific patches from IBM Fix Central immediately to remediate the underlying risk of unauthorized script execution and restore the integrity of the security control sphere.