Summary
CVE-2026-78401 is a critical deserialization of untrusted data vulnerability (CWE-502) in IBM Security Verify Access and IBM Verify Identity Access. A remote, unauthenticated attacker could execute arbitrary code on an affected system. The CVSS v3.1 base score is 9.8 (Critical).
Technical details
- Root cause: deserialization of untrusted data (CWE-502).
- Trigger conditions: no authentication and no user interaction are required.
- Attack vector: network, low attack complexity.
- Impact: remote arbitrary code execution, with high impact to confidentiality, integrity and availability.
Affected software
- IBM Security Verify Access 10.0 through 10.0.9.2
- IBM Verify Identity Access 11.0 through 11.0.3
- Container variants of both products in the same version ranges
Severity
CVSS v3.1 base score 9.8 (Critical): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: upgrade to IBM Verify Identity Access 11.0.3.1 or IBM Security Verify Access 10.0.9.3. For container deployments, apply the updates described in IBM’s documentation.
- Details are in IBM’s security bulletin (see references).
- No workarounds were identified in the sources reviewed. Until patched, consider restricting network access to affected systems.

