CVE-2026-17616
published 2026-08-12CVE-2026-17616: IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.27%
19.5th percentile
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | — | — |
| ibm | security_verify_access | — | — |
| ibm | security_verify_access | 10.0 – 10.0.9.2 | — |
| ibm | security_verify_access | >= 10.0.0 < 10.0.9.2 | 10.0.9.2 |
| ibm | security_verify_access_container | 10.0 – 10.0.9.2 | — |
| ibm | security_verify_access_container | 10.0.0.0 – 10.0.9.2 | — |
| ibm | verify_identity_access | — | — |
| ibm | verify_identity_access | >= 11.0 < 11.0.3 | 11.0.3 |
| ibm | verify_identity_access | 11.0 – 11.0.3 | — |
| ibm | verify_identity_access_container | 11.0 – 11.0.3 | — |
| ibm | verify_identity_access_container | 11.0.0.0 – 11.0.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations
ghsa_unreviewed·2026-08-12
CVE-2026-17616 [MEDIUM] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
VulDB
IBM Security Verify Access Reverse Proxy inadequate encryption
vuldb·2026-08-12·CVSS 6.8
CVE-2026-17616 [MEDIUM] IBM Security Verify Access Reverse Proxy inadequate encryption
A vulnerability, which was classified as problematic, has been found in IBM Security Verify Access, Verify Identity Access and Verify Identity Access Container. This affects an unknown function of the component Reverse Proxy. The manipulation leads to inadequate encryption strength.
This vulnerability is listed as CVE-2026-17616. The attack may be initiated remotely. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-12
Published