CVE-2026-12005
published 2026-08-12CVE-2026-12005: IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through…
PriorityP346high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.37%
30.9th percentile
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | — | — |
| ibm | security_verify_access | 10.0 – 10.0.9.2 | — |
| ibm | security_verify_access | 10.0.0 – 10.0.9.2 | — |
| ibm | security_verify_access_container | 10.0 – 10.0.9.2 | — |
| ibm | verify_identity_access | 11.0 – 11.0.3 | — |
| ibm | verify_identity_access_container | 11.0 – 11.0.3 | — |
| ibm | verify_identity_access_container | 11.0.0.0 – 11.0.3.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerabili
ghsa_unreviewed·2026-08-12
CVE-2026-12005 [HIGH] CWE-78 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerabili
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
VulDB
IBM Security Verify Access Management Interface privileges management
vuldb·2026-08-12·CVSS 7.2
CVE-2026-12005 [HIGH] IBM Security Verify Access Management Interface privileges management
A vulnerability marked as very critical has been reported in IBM Security Verify Access, Verify Identity Access and Verify Identity Access Container. Affected by this issue is some unknown functionality of the component Management Interface. The manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-12005. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-12
Published