CVE-2026-12359 – IBM Security Verify Access

CVSS 8.1 IMPORTANT High with EoP or RCE – Expedited Deployment

“Management and access-control weaknesses can expose sensitive data, disrupt services, and expand attacker privileges.”

IBM Security Verify Access, Verify Identity Access, and Verify Identity Access Container are affected by six high-severity vulnerabilities. CVE-2026-12004 has a CVSS score of 8.7, High severity and can cause information disclosure and denial of service through a malicious HTTP request. CVE-2026-12359 and CVE-2026-13267 each have a CVSS score of 8.1, High severity and can expose sensitive information or allow an authenticated user to gain another user's privileges.

CVE-2026-11923 has a CVSS score of 7.4, High severity and involves weaker-than-expected cryptographic validation. CVE-2026-12005 and CVE-2026-12618 each have a CVSS score of 7.2, High severity and can allow privileged users to perform additional operations or commands through improper input validation.

Key Details

Affected Product
Ibm Security Verify Access
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-287
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.