PT-2026-108238 · Ibm · Ibm Security Verify Access+3

CVE-2026-78406

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78406

Affected Products

Ibm Security Verify Access
Ibm Security Verify Access Container
Verify Identity Access
Ibm Verify Identity Access Container