Back to database
Soon55Medium5.5VulnerabilityCVE-2026-12109No patch link observed

CVE-2026-12109 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an attacker with administrative pri…

Published Oct 8, 2026, 09:17 PM UTCIngested 2h agoSource NVD(cve-db)CVE-2026-12109

Description

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an attacker with administrative privileges and access to the local management interface to execute arbitrary code due to an unbounded write to a fixed-size stack buffer.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H
5.5

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

High

Attack Complexity

PR

High

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

Low

Confidentiality

I

Low

Integrity

A

High

Availability