A critical improper authentication flaw (CVSS 9.1) in IBM Security Verify Access and IBM Verify Identity Access could let a remote, unauthenticated attacker bypass authentication.
What Is It
CVE-2026-19491 is an authentication bypass vulnerability classified as CWE-287 (Improper Authentication). According to IBM's description in the NVD record, a remote attacker could bypass authentication in IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3.
IBM PSIRT gave it a CVSS v3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. NVD published the record on 2026-10-08, and its status is currently "Awaiting Analysis."
Why It Matters
The CVSS metrics show a low barrier to attack:
- Attack Vector: Network. It can be exploited remotely.
- Attack Complexity: Low. No special conditions are required.
- Privileges Required: None. No account is needed.
- User Interaction: None. No victim action is needed.
A successful attack has high impact on confidentiality and integrity. Availability is not affected. These products handle access and identity, so an authentication bypass here weakens the control that is meant to protect other resources.
The CISA KEV entry supplied for this CVE is empty, so the source material does not confirm active exploitation.
What's Vulnerable
The NVD record lists these affected IBM products:
| Product | Affected Versions |
|---|---|
| IBM Security Verify Access | 10.0 through 10.0.9.2 |
| IBM Security Verify Access Container | 10.0 through 10.0.9.2 |
| IBM Verify Identity Access | 11.0 through 11.0.3 |
| IBM Verify Identity Access Container | 11.0 through 11.0.3 |
Both the appliance/software editions and the container editions are affected.
Patch Status
The supplied NVD data does not name fixed versions or specific remediation steps. IBM has published a security bulletin for this issue, linked below. Organizations running any affected version should check that advisory for fix and mitigation guidance and treat this as a priority, given the critical severity and the lack of any authentication requirement.
No CISA KEV required action or due date applies, because the supplied KEV entry is empty.