CVE-2026-16916 is a critical (CVSS 9.1) protection mechanism failure in IBM Security Verify Access and IBM Verify Identity Access that could let a remote authenticated attacker execute arbitrary code.
What Is It
CVE-2026-16916 affects IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. According to the NVD record, it "could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure." The weakness is classified as CWE-693 (Protection Mechanism Failure).
IBM PSIRT published the record on 2026-10-08. As of publication, NVD lists its status as "Awaiting Analysis."
Why It Matters
IBM PSIRT gave the flaw a CVSS v3.1 base score of 9.1 (CRITICAL). The vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H:
- Network-reachable with low attack complexity
- High privileges required, so the attacker must already be authenticated with elevated access
- No user interaction needed
- Scope changed, so impact can reach beyond the vulnerable component
- High impact to confidentiality, integrity and availability
The high-privilege requirement limits who can exploit it. Even so, these products control identity and access, so code execution on them could expose the systems they protect.
What's Vulnerable
According to IBM's affected-product data in the NVD record:
| Product | Affected Versions |
|---|---|
| IBM Security Verify Access | 10.0 through 10.0.9.2 |
| IBM Security Verify Access Container | 10.0 through 10.0.9.2 |
| IBM Verify Identity Access | 11.0 through 11.0.3 |
| IBM Verify Identity Access Container | 11.0 through 11.0.3 |
Patch Status
The NVD record does not list fixed versions or specific remediation steps. IBM has published a security bulletin for this issue (node 7291628). Administrators should read it for fix availability and upgrade guidance.
Until patches are applied, organizations running affected versions should:
- Review IBM's bulletin
- Find all appliance and container deployments
- Restrict and audit high-privilege accounts on these systems