Sceawere
Vulnerability Detail
CVE-2026-11923UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM Verify Cryptographic Validation Weakness
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- Security Verify Access
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-08-12T20:17:33.250Z",
"pubdate": "2026-08-12T20:17:33.250Z",
"executiveSummary": "A cryptographic validation vulnerability exists in the Reverse Proxy component of IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and IBM Verify Identity Access Container 11.0 through 11.0.3 when configured in certain ways. The flaw arises from the application providing weaker than expected cryptographic validation of user-supplied data. This security deficiency impacts the integrity and authenticity guarantees of processed cryptographic operations, potentially exposing the affected identity and access management infrastructure to data tampering or validation bypass scenarios. An adversary capable of manipulating user-supplied data destined for cryptographic processing could exploit this weakness under specific non-default or standard deployment configurations. The risk implications include the potential degradation of trust boundaries enforced by the reverse proxy, compromising session tokens, assertions, or signed payloads depending on the exact operational context. Successful exploitation requires specific configuration prerequisites and network reachability to the vulnerable reverse proxy endpoint handling the cryptographic routines.",
"technicalDetails": "The vulnerability resides within the cryptographic validation logic implemented by the Reverse Proxy component across multiple versions of IBM Security Verify Access and IBM Verify Identity Access. Specifically, the root cause involves insufficient or improperly parameterized cryptographic verification routines applied to user-supplied data inputs. In cryptographic engineering, robust verification requires strict enforcement of digital signatures, message authentication codes, or cryptographic checksums using strong algorithms and parameters. When the reverse proxy performs weaker than expected validation, it fails to rigorously verify the authenticity, integrity, or structural correctness of incoming data payloads.\nThe affected components include the Reverse Proxy in IBM Security Verify Access versions 10.0 through 10.0.9.2, IBM Verify Identity Access versions 11.0 through 11.0.3, and the corresponding IBM Verify Identity Access Container versions 11.0 through 11.0.3. This vulnerability manifests primarily under certain administrative configurations where the reverse proxy processes external requests containing user-supplied data intended for cryptographic scrutiny.\nThe attack flow proceeds as follows: First, an attacker identifies an endpoint exposed by the reverse proxy that processes user-supplied data utilizing the weak cryptographic validation mechanism. Second, the attacker crafts a malicious or altered payload designed to bypass the lax validation checks, such as submitting modified assertions, tokens, or encrypted parameters without possessing the correct cryptographic material or keys. Third, the reverse proxy evaluates the incoming data against the flawed cryptographic validation logic. Because the validation is weaker than expected, the reverse proxy improperly accepts the tampered user-supplied data as authentic.\nDepending on the specific architectural integration and payload behavior, post-exploitation impact can range from the circumvention of security controls to the acceptance of unauthorized state or identity assertions. The network exposure is tied directly to the interfaces exposed by the reverse proxy handling incoming client traffic. Authentication and privilege requirements vary based on the specific feature or endpoint targeted, but the core vulnerability stems entirely from the internal inadequacy of the cryptographic validation checks performed by the affected software."
}