CVE-2026-8861
published 2026-07-17CVE-2026-8861: IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This…
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.24%
15.3th percentile
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | 10.0 – 10.0.9.1 | — |
| ibm | security_verify_access_container | 10.0 – 10.0.9.1 | — |
| ibm | verify_identity_access | 11.0 – 11.0.2 | — |
| ibm | verify_identity_access_container | 11.0 – 11.0.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Security Verify Error Message error_response information disclosure
vuldb·2026-07-18·CVSS 5.3
CVE-2026-8861 [MEDIUM] IBM Security Verify Error Message error_response information disclosure
A vulnerability, which was classified as problematic, has been found in IBM Security Verify. This affects the function error_response of the component Error Message Handler. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-8861. The attack may be initiated remotely. There is no available exploit.
GHSA
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
ghsa_unreviewed·2026-07-17
CVE-2026-8861 [MEDIUM] CWE-209 IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-17
Published