CVE-2026-1346
published 2026-04-08CVE-2026-1346: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0…
PriorityP346high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.5th percentile
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | 10.0 – 10.0.9.1 | — |
| ibm | security_verify_access | 10.0.0 – 10.0.9.1 | — |
| ibm | security_verify_access_container | 10.0 – 10.0.9.1 | — |
| ibm | security_verify_access_container | 10.0.0.0 – 10.0.9.1 | — |
| ibm | verify_identity_access | 11.0 – 11.0.2 | — |
| ibm | verify_identity_access | 11.0.0.0 – 11.0.2.0 | — |
| ibm | verify_identity_access_container | 11.0 – 11.0.2 | — |
| ibm | verify_identity_access_container | 11.0.0.0 – 11.0.2.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Verify Identity Access Container unnecessary privileges (CNNVD-202604-1895)
vuldb·2026-04-10·CVSS 9.3
CVE-2026-1346 [CRITICAL] IBM Verify Identity Access Container unnecessary privileges (CNNVD-202604-1895)
A vulnerability was found in IBM Verify Identity Access Container, Security Verify Access Container, Verify Identity Access and Security Verify Access. It has been rated as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in execution with unnecessary privileges.
This vulnerability is identified as CVE-2026-1346. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-x64c-qgm9-xp36: IBM Verify Identity Access Container 11
ghsa_unreviewed·2026-04-08
CVE-2026-1346 [CRITICAL] CWE-250 GHSA-x64c-qgm9-xp36: IBM Verify Identity Access Container 11
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
blogs_hackernews·2026-04-13·CVSS 8.6
[HIGH] ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is one of those mornings where the gap between a quiet shift and a full-blown incident response is basically non-existent.
The variety this week is particularly nasty. We have AI models being turned into autonomous exploit engines, North Korean groups playing the long game
Wiz
CVE-2026-1342 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2026-1342 [HIGH] CVE-2026-1342 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1342 :
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
Source : NVD
## 7.9
Score
Published April 8, 2026
Severity HIGH
CNA Score 8.5
Affected Technologies
IBM Security Verify Access (formerly ISAM)
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Wiz
CVE-2026-1343 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2026-1343 [HIGH] CVE-2026-1343 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1343 :
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.
Source : NVD
## 7.2
Score
Published April 8, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
IBM Security Verify Access (formerly ISAM)
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.3
Exploitation Probability (EPSS) N/A
Affected packages and librarie
Wiz
CVE-2026-1346 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2026-1346 [HIGH] CVE-2026-1346 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1346 :
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.
Source : NVD
## 7.8
Score
Published April 8, 2026
Severity HIGH
CNA Score 9.3
Affected Technologies
IBM Security Verify Access (formerly ISAM)
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
2026-04-08
Published