CVE-2026-17616
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-310
- Published
- 2026-08-12
- Last modified
- 2026-08-12
Affected products
- IBM Security Verify Access
- IBM Verify Identity Access
- IBM Verify Identity Access Container
- IBM Security Verify Access Container
Weakness type
Related vulnerabilities
- CVE-2026-86280 — SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storage
- CVE-2026-82699 — sambitraj Student Management System Password aca.sql cleartext storage
- CVE-2026-82555 — TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
- CVE-2026-81836 — RooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmission
- CVE-2026-77151 — lin-snow Ech0 crypto.go MD5Encrypt risky encryption
- CVE-2026-19896 — mangroup dtale Flask Session Cookie app.py build_secret_key random values
- CVE-2026-19891 — TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption
- CVE-2026-18591 — Meesho Online Shopping App com.meesho.supply cleartext storage