IBM disclosed two high-severity vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access that affect both containerized and non-containerized deployments. CVE-2026-1342 is classified as CWE-829 and allows execution of malicious scripts from outside the product's control sphere, while CVE-2026-1346 is a CWE-250 flaw that can let a locally authenticated user escalate privileges to root because the software runs with more privileges than necessary.
The affected products and versions listed for CVE-2026-1346 include IBM Verify Identity Access Container 11.0 through 11.0.2, IBM Security Verify Access Container 10.0 through 10.0.9.1, IBM Verify Identity Access 11.0 through 11.0.2, and IBM Security Verify Access 10.0 through 10.0.9.1. IBM published advisories for both issues, and the reported CVSS v3.1 metrics indicate significant risk, with CVE-2026-1346 carrying high impact across confidentiality, integrity, and availability and CVE-2026-1342 exposing systems to unauthorized script execution within affected environments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
IBM disclosed multiple additional vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access, including HTTP request smuggling flaws CVE-2026-2862 and CVE-2026-1491, plus issues such as buffer overflow, command injection, authentication bypass, SSRF, and XSS. IBM urged customers to upgrade to IBM Verify Identity Access v11.0.2 IF1, IBM Security Verify Access v10.0.9.1 IF1, and updated container images, stating no workarounds were available.
IBM published advisories for two vulnerabilities affecting IBM Verify Identity Access and IBM Security Verify Access, including containerized and non-containerized versions. CVE-2026-1342 allows execution of malicious scripts by a locally authenticated user, while CVE-2026-1346 allows local privilege escalation to root due to excessive privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.