CVE-2026-11923
published 2026-08-12CVE-2026-11923: IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through…
PriorityP347high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.32%
22.7th percentile
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | — | — |
| ibm | security_verify_access | 10.0 – 10.0.9.2 | — |
| ibm | security_verify_access | 10.0.0 – 10.0.9.2 | — |
| ibm | security_verify_access_container | 10.0 – 10.0.9.2 | — |
| ibm | verify_identity_access | 11.0 – 11.0.3 | — |
| ibm | verify_identity_access_container | 11.0 – 11.0.3 | — |
| ibm | verify_identity_access_container | 11.0.0.0 – 11.0.3.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations
ghsa_unreviewed·2026-08-12
CVE-2026-11923 [HIGH] CWE-287 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
VulDB
IBM Security Verify Access up to 10.0.9.2/11.0.3 Reverse Proxy inadequate encryption
vuldb·2026-08-12·CVSS 7.4
CVE-2026-11923 [HIGH] IBM Security Verify Access up to 10.0.9.2/11.0.3 Reverse Proxy inadequate encryption
A vulnerability classified as problematic has been found in IBM Security Verify Access, Security Verify Access Container, Verify Identity Access and Verify Identity Access Container up to 10.0.9.2/11.0.3. This vulnerability affects unknown code of the component Reverse Proxy. This manipulation causes inadequate encryption strength.
This vulnerability is tracked as CVE-2026-11923. The attack is possible to be carried out remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-12
Published