Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-19491 2026-10-08

CVE-2026-19491: Critical Authentication Bypass in IBM Security Verify Access and Verify Identity Access

"A critical improper authentication flaw (CVSS 9.1) in IBM Security Verify Access and IBM Verify Identity Access could let a remote, unauthenticated attacker bypass authentication."

A critical improper authentication flaw (CVSS 9.1) in IBM Security Verify Access and IBM Verify Identity Access could let a remote, unauthenticated attacker bypass authentication.

What Is It

CVE-2026-19491 is an authentication bypass vulnerability classified as CWE-287 (Improper Authentication). According to IBM's description in the NVD record, a remote attacker could bypass authentication in IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3.

IBM PSIRT gave it a CVSS v3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. NVD published the record on 2026-10-08, and its status is currently "Awaiting Analysis."

Why It Matters

The CVSS metrics show a low barrier to attack:

A successful attack has high impact on confidentiality and integrity. Availability is not affected. These products handle access and identity, so an authentication bypass here weakens the control that is meant to protect other resources.

The CISA KEV entry supplied for this CVE is empty, so the source material does not confirm active exploitation.

What's Vulnerable

The NVD record lists these affected IBM products:

Product Affected Versions
IBM Security Verify Access 10.0 through 10.0.9.2
IBM Security Verify Access Container 10.0 through 10.0.9.2
IBM Verify Identity Access 11.0 through 11.0.3
IBM Verify Identity Access Container 11.0 through 11.0.3

Both the appliance/software editions and the container editions are affected.

Patch Status

The supplied NVD data does not name fixed versions or specific remediation steps. IBM has published a security bulletin for this issue, linked below. Organizations running any affected version should check that advisory for fix and mitigation guidance and treat this as a priority, given the critical severity and the lack of any authentication requirement.

No CISA KEV required action or due date applies, because the supplied KEV entry is empty.

Sources