CVE-2026-16823 is a critical (CVSS 9.1) improper authentication flaw in IBM Security Verify Access and IBM Verify Identity Access. A remote, unauthenticated attacker could use it to bypass security restrictions.
What Is It
IBM's PSIRT published CVE-2026-16823 on October 8, 2026. It is classified as CWE-287, Improper Authentication. According to the NVD description, IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 "could allow a remote attacker to bypass security restrictions due to improper authentication."
The NVD record is in "Awaiting Analysis" status, so NVD has not yet published its own assessment. The score and details below come from IBM as the CNA.
Why It Matters
IBM rates the flaw 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. In practice that means:
- Network-reachable: the attacker needs no local access.
- Low attack complexity
- No privileges or user interaction required
- High impact on confidentiality and integrity
These products handle authentication and access control. A bypass in that layer could let an attacker get past the controls that protect other systems.
There is currently no CISA KEV entry for this CVE, so active exploitation has not been confirmed through KEV.
What's Vulnerable
The NVD record lists these IBM products as affected:
| Product | Affected Versions |
|---|---|
| IBM Security Verify Access | 10.0 through 10.0.9.2 |
| IBM Security Verify Access Container | 10.0 through 10.0.9.2 |
| IBM Verify Identity Access | 11.0 through 11.0.3 |
| IBM Verify Identity Access Container | 11.0 through 11.0.3 |
Both the appliance/software editions and the container editions are affected.
Patch Status
The source data does not name a fixed version or a specific remediation step. The record links to an IBM support advisory (node 7291628), which is where to get IBM's fix and remediation guidance. CISA has not set a required action or due date because the CVE is not in the KEV catalog.
Organizations running affected versions should: - Review the IBM advisory. - Apply the vendor's remediation as a priority, given the critical score and the unauthenticated network attack vector.