CVE-2026-1346 – IBM Verify Identity Access Container Security Update Fixes High and Critical Vulnerabilities
“Identity systems failed at the gate, exposing the very controls meant to protect access.”
IBM has released a security update for Verify Identity Access Container addressing two serious vulnerabilities: CVE-2026-1342 and CVE-2026-1346. These issues impact identity and access control mechanisms, potentially allowing unauthorized actions within authentication workflows. CVE-2026-1342 has a CVSS score of 8.5, which is High severity. CVE-2026-1346 has a CVSS score of 9.3, which is Critical severity.
While no active exploitation has been verified, the nature of these vulnerabilities in identity infrastructure raises significant risk. If left unpatched, attackers could undermine authentication controls or escalate privileges within protected environments, directly affecting enterprise security posture.
Key Details
- Affected Product
- Ibm Security Verify Access
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-250