CVE-2026-12101
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.14%
- CWE
- CWE-289
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- IBM Verify Identity Access
- IBM Security Verify Access
- IBM Verify Identity Access Container
- IBM Security Verify Access Container
Weakness type
Related vulnerabilities
- CVE-2021-34746 — Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
- CVE-2025-29266 — Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication
- CVE-2024-56511 — DataEase has an unauthorized vulnerability
- CVE-2023-20046 — A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remot
- CVE-2026-8457 — WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
- CVE-2026-15980 — MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
- CVE-2025-13613 — Elated Membership <= 1.2 - Authentication Bypass via Social Login
- CVE-2026-9701 — Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation