Summary
CVE-2026-16823 is an improper authentication vulnerability (CWE-287) in IBM Security Verify Access and IBM Verify Identity Access. A remote attacker can bypass security restrictions without privileges or user interaction. The CVSS v3.1 base score is 9.1 (Critical).
Technical details
- Root cause: improper authentication (CWE-287) in the product’s authentication mechanisms.
- Trigger conditions: none beyond network reachability of the affected product. No privileges and no user interaction are required, and attack complexity is low.
- Attack vector: network.
- Impact: high confidentiality and high integrity impact. There is no availability impact.
- Further technical detail, such as the specific affected component or exploitation method, was not published in the CVE record.
Affected software
- IBM Security Verify Access: 10.0 through 10.0.9.2
- IBM Verify Identity Access: 11.0 through 11.0.3
- IBM Security Verify Access Container: 10.0 through 10.0.9.2
- IBM Verify Identity Access Container: 11.0 through 11.0.3
Severity
CVSS v3.1 base score: 9.1 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: upgrade IBM Verify Identity Access to 11.0.3.1, or IBM Security Verify Access to 10.0.9.3. For container deployments, apply the container updates described in IBM’s advisory.
- Follow the IBM security bulletin for the exact fix packages and installation instructions.
- No workarounds are listed in the sources reviewed. Until patching is complete, restrict network access to the affected instances where feasible.

