Sceawere
Vulnerability Detail
CVE-2026-12005UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM Verify Access Management Interface Input Validation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- IBM
- Product
- Security Verify Access
- Attack Type
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-08-12T20:17:33.667Z",
"pubdate": "2026-08-12T20:17:33.667Z",
"executiveSummary": "An input validation vulnerability has been identified within the management interface of IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and IBM Verify Identity Access Container 11.0 through 11.0.3. This vulnerability allows an authenticated attacker possessing existing administrative or management privileges to execute unauthorized additional operations by supplying maliciously crafted HTTP requests to the system. The risk implication centers on privilege abuse and potential unauthorized administrative actions within the affected identity and access management infrastructure. Successful exploitation requires the attacker to already hold privileged access to the management interface, meaning the attack vector relies on credentialed access combined with improper sanitization or validation of input parameters processed by the underlying management backend. The impact includes the potential bypass of intended operational boundaries and unauthorized execution of privileged commands via the management interface.",
"technicalDetails": "The vulnerability stems from insufficient input validation within the management interface of the affected IBM products. Specifically, the management interface fails to properly sanitize, validate, or restrict input parameters supplied via HTTP requests processed by the application logic. The vulnerable component resides in the administrative handling routines of the management interface across IBM Security Verify Access versions 10.0 through 10.0.9.2, IBM Verify Identity Access versions 11.0 through 11.0.3, and IBM Verify Identity Access Container versions 11.0 through 11.0.3. Exploitation of this flaw requires network exposure to the administrative management interface and necessitates that the attacker is already authenticated with specific administrative or privileged roles. The attack flow begins when a privileged attacker crafts a malicious HTTP request containing unexpected or malformed input parameters targeting the management interface endpoints. Because the backend code lacks rigorous input validation and boundary enforcement, the crafted request is processed by the application. This improper handling allows the privileged attacker to coerce the management interface into executing additional operations that exceed their intended authorization scope or bypass secondary validation checks. The payload behavior involves manipulating HTTP request parameters to trigger unintended administrative or system-level actions. The post-exploitation impact includes unauthorized execution of restricted functions, potential state manipulation of the identity and access management infrastructure, and an escalation of privileges within the administrative domain, enabling the attacker to perform actions outside their designated operational constraints."
}