Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-16823 2026-10-08

IBM Security Verify Access and Verify Identity Access Hit by Critical Authentication Bypass (CVE-2026-16823)

"CVE-2026-16823 is a critical (CVSS 9.1) improper authentication flaw in IBM Security Verify Access and IBM Verify Identity Access. A remote, unauthenticated attacker could use it to bypass security restrictions."

CVE-2026-16823 is a critical (CVSS 9.1) improper authentication flaw in IBM Security Verify Access and IBM Verify Identity Access. A remote, unauthenticated attacker could use it to bypass security restrictions.

What Is It

IBM's PSIRT published CVE-2026-16823 on October 8, 2026. It is classified as CWE-287, Improper Authentication. According to the NVD description, IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 "could allow a remote attacker to bypass security restrictions due to improper authentication."

The NVD record is in "Awaiting Analysis" status, so NVD has not yet published its own assessment. The score and details below come from IBM as the CNA.

Why It Matters

IBM rates the flaw 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. In practice that means:

These products handle authentication and access control. A bypass in that layer could let an attacker get past the controls that protect other systems.

There is currently no CISA KEV entry for this CVE, so active exploitation has not been confirmed through KEV.

What's Vulnerable

The NVD record lists these IBM products as affected:

Product Affected Versions
IBM Security Verify Access 10.0 through 10.0.9.2
IBM Security Verify Access Container 10.0 through 10.0.9.2
IBM Verify Identity Access 11.0 through 11.0.3
IBM Verify Identity Access Container 11.0 through 11.0.3

Both the appliance/software editions and the container editions are affected.

Patch Status

The source data does not name a fixed version or a specific remediation step. The record links to an IBM support advisory (node 7291628), which is where to get IBM's fix and remediation guidance. CISA has not set a required action or due date because the CVE is not in the KEV catalog.

Organizations running affected versions should: - Review the IBM advisory. - Apply the vendor's remediation as a priority, given the critical score and the unauthenticated network attack vector.

Sources