CVE-2026-12101 vulnerability in IBM Products
Published on September 15, 2026
Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.
Weakness Type
Authentication Bypass by Alternate Name
The software performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.
Products Associated with CVE-2026-12101
Want to know whenever a new CVE is published for IBM products? stack.watch will email you.
Affected Versions
IBM Verify Identity Access:- Version 11.0.0, <= 11.0.3 Interim Fix 001 is affected.
- Version 10.0.0, <= 10.0.9.2 Interim Fix 001 is affected.
- Version 11.0.0, <= 11.0.3 Interim Fix 001 is affected.
- Version 10.0.0, <= 10.0.9.2 Interim Fix 001 is affected.