CVE-2026-1346 – IBM Verify Identity Access Container Security Update Fixes High and Critical Vulnerabilities

CVSS 9.3 CRITICAL

“Identity systems failed at the gate, exposing the very controls meant to protect access.”

IBM has released a security update for Verify Identity Access Container addressing two serious vulnerabilities: CVE-2026-1342 and CVE-2026-1346. These issues impact identity and access control mechanisms, potentially allowing unauthorized actions within authentication workflows. CVE-2026-1342 has a CVSS score of 8.5, which is High severity. CVE-2026-1346 has a CVSS score of 9.3, which is Critical severity.

While no active exploitation has been verified, the nature of these vulnerabilities in identity infrastructure raises significant risk. If left unpatched, attackers could undermine authentication controls or escalate privileges within protected environments, directly affecting enterprise security posture.

Key Details

Affected Product
Ibm Security Verify Access
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-250
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.