IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow an unauthenticated user to execute arbitrary commands as lower user privileges on the system due to improper validation of user supplied input.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7268253 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Apr 2026, 16:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ibm security Verify Access
Ibm verify Identity Access Container Ibm security Verify Access Container Ibm Ibm verify Identity Access |
|
| CPE | cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:* cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:* |
|
| References | () https://www.ibm.com/support/pages/node/7268253 - Vendor Advisory |
01 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 21:16
Updated : 2026-04-07 16:26
NVD link : CVE-2026-1345
Mitre link : CVE-2026-1345
CVE.ORG link : CVE-2026-1345
JSON object : View
Products Affected
ibm
- verify_identity_access_container
- security_verify_access
- security_verify_access_container
- verify_identity_access
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
