CVE-2026-12358
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.39%
- CWE
- CWE-674
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- IBM Verify Identity Access
- IBM Security Verify Access
- IBM Verify Identity Access Container
- IBM Security Verify Access Container
Weakness type
Related vulnerabilities
- CVE-2026-33498 — Parse Server: Query condition depth bypass via pre-validation transform pipeline
- CVE-2026-32944 — Parse Server crash via deeply nested query condition operators
- CVE-2025-66031 — node-forge ASN.1 Unbounded Recursion
- CVE-2025-54858 — BIG-IP Advanced WAF and ASM vulnerability
- CVE-2025-9624 — OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS
- CVE-2026-33508 — Parse Server: LiveQuery subscription query depth bypass
- CVE-2026-72686 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
- CVE-2026-72679 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service