CRITICAL🇵🇱 Wersja polska

CVE-2026-1346

CVSS 9.3v3.1pub. 2026-04-08upd. 2026-07-25

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-250 (Execution with Unnecessary Privileges) involves components of IBM Security Verify Access and IBM Verify Identity Access running with higher privileges than actually required for their operation. A locally authenticated user can exploit this to elevate their privileges to root level without needing additional administrative privileges. This affects both containerized and traditional installations of both products.

Impact

An attacker with local access to the system can gain full control of the operating system with root privileges, enabling them to read, modify and delete any data, as well as perform further actions in the infrastructure.

Mitigation & patch

Apply patches available from the vendor according to the references (https://www.ibm.com/support/pages/node/7268253). Additionally, it is recommended to restrict local access to systems hosting these products exclusively to trusted and necessary users, and to monitor privilege escalation attempts.

Who is affected

IBM Verify Identity Access versions 11.0 to 11.0.2, IBM Security Verify Access versions 10.0 to 10.0.9.1, IBM Verify Identity Access Container versions 11.0 to 11.0.2, and IBM Security Verify Access Container versions 10.0 to 10.0.9.1.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • IBM Security Verify Access

    APP
    Ibm
    10.0.0 – 10.0.9.1
  • IBM Security Verify Access Container

    APP
    Ibm
    10.0.0.0 – 10.0.9.1
  • IBM Verify Identity Access

    APP
    Ibm
    11.0.0.0 – 11.0.2.0
  • IBM Verify Identity Access Container

    APP
    Ibm
    11.0.0.0 – 11.0.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2025-36356CRITICAL9.3PL ✓same product

IBM Security Verify Access — privilege escalation do root przez nadmiarowe uprawnienia

CVE-2024-49806CRITICAL9.4PL ✓same product

IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2024-49805CRITICAL9.4PL ✓same product

IBM Security Verify Access — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2024-49803CRITICAL9.8PL ✓same product

IBM Security Verify Access — zdalne wykonanie poleceń (command injection)

CVE-2021-39070CRITICAL9.8PL ✓same product

IBM Security Verify Access — obejście uwierzytelnienia jako dowolny użytkownik