CVE-2026-4101
8.1IBM · Verify Identity Access / Security Verify Access
Certain IBM Verify Identity and Security Verify Access products contain an authentication bypass vulnerability that may be triggered under specific load conditions.
Executive summary
An authentication bypass vulnerability in IBM Verify Identity and Security Verify Access products could allow an unauthenticated attacker to gain unauthorized access to the application.
Vulnerability
The vulnerability is classified as an Improper Authentication flaw (CWE-287), where specific system load conditions allow an unauthenticated remote attacker to circumvent authentication controls.
Business impact
Successful exploitation of this flaw grants an attacker unauthorized access to the application, which may lead to the compromise of sensitive identity data and administrative functions. Given the CVSS score of 8.1, the vulnerability is considered High severity, as it facilitates full access to the identity management environment without requiring valid credentials.
Remediation
Immediate Action: Update to the provided fixed versions immediately: IBM Verify Identity Access v11.0.2 IF1 or IBM Security Verify Access v10.0.9.1 IF1 via the IBM Fix Central portal.
Proactive Monitoring: Review system authentication logs for unusual login patterns or unauthorized access attempts that coincide with high system load periods.
Compensating Controls: Ensure that the application is not exposed to the public internet and restrict access to authorized network segments while the update process is underway.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability presents a significant risk to identity infrastructure by removing the barrier of authentication. Administrators should prioritize the deployment of the specified interim fixes (IF1) across all affected environments to mitigate the risk of unauthorized access.