---
id: CVE-2026-12109
title: >-
  IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity
  Access 11.0 through 11.0.3 could allow an attacker with administrative
  privileges and access to the local management interface to execute arbitrary
  code due to an u…
summary: >-
  IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity
  Access 11.0 through 11.0.3 could allow an attacker with administrative
  privileges and access to the local management interface to execute arbitrary
  code due to an u…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H'
cwe:
  - CWE-787
vendor: ibm
product: security_verify_access
affected:
  - 'security_verify_access >= 10.0.0, < 10.0.9.3'
  - 'security_verify_access_container >= 10.0.0.0, <= 10.0.9.2'
  - 'verify_identity_access >= 11.0, < 11.0.3.1'
  - 'verify_identity_access_container >= 11.0.0.0, <= 11.0.3.0'
patched:
  - security_verify_access 10.0.9.3
  - verify_identity_access 11.0.3.1
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T14:25:25.543'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12109'
references:
  - url: 'https://www.ibm.com/support/pages/node/7291628'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00197
epssPercentile: 0.08668
ingestedAt: '2026-10-08T22:11:53.861Z'
---

## Overview

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an attacker with administrative privileges and access to the local management interface to execute arbitrary code due to an unbounded write to a fixed-size stack buffer.

## Affected

- `security_verify_access >= 10.0.0, < 10.0.9.3`
- `security_verify_access_container >= 10.0.0.0, <= 10.0.9.2`
- `verify_identity_access >= 11.0, < 11.0.3.1`
- `verify_identity_access_container >= 11.0.0.0, <= 11.0.3.0`

## Remediation

Upgrade past the affected range:

- `security_verify_access 10.0.9.3`
- `verify_identity_access 11.0.3.1`
