CVE-2026-4938
published 2026-07-17CVE-2026-4938: IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.17%
7.2th percentile
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned permissions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | 10.0 – 10.0.9.1 | — |
| ibm | security_verify_access_container | 10.0 – 10.0.9.1 | — |
| ibm | verify_identity_access | 11.0 – 11.0.2 | — |
| ibm | verify_identity_access_container | 11.0 – 11.0.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Containe
ghsa_unreviewed·2026-07-17
CVE-2026-4938 [MEDIUM] CWE-863 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Containe
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned permissions.
VulDB
IBM Verify Identity Access Permissions permission
vuldb·2026-07-17·CVSS 6.5
CVE-2026-4938 [MEDIUM] IBM Verify Identity Access Permissions permission
A vulnerability marked as critical has been reported in IBM Verify Identity Access, Security Verify Access, Verify Identity Access Container and Security Verify Access Container. This vulnerability affects unknown code of the component Permissions. The manipulation leads to permission issues.
This vulnerability is listed as CVE-2026-4938. The attack may be initiated remotely. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published