CVE-2026-12004 – IBM Security Verify Access
“Management and access-control weaknesses can expose sensitive data, disrupt services, and expand attacker privileges.”
IBM Security Verify Access, Verify Identity Access, and Verify Identity Access Container are affected by six high-severity vulnerabilities. CVE-2026-12004 has a CVSS score of 8.7, High severity and can cause information disclosure and denial of service through a malicious HTTP request. CVE-2026-12359 and CVE-2026-13267 each have a CVSS score of 8.1, High severity and can expose sensitive information or allow an authenticated user to gain another user's privileges.
CVE-2026-11923 has a CVSS score of 7.4, High severity and involves weaker-than-expected cryptographic validation. CVE-2026-12005 and CVE-2026-12618 each have a CVSS score of 7.2, High severity and can allow privileged users to perform additional operations or commands through improper input validation.
Key Details
- Affected Product
- Ibm Security Verify Access
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-134