CVE-2026-78401 is a critical (CVSS 9.8) flaw in IBM Security Verify Access and IBM Verify Identity Access: the products deserialize untrusted data, which could let a remote attacker execute arbitrary code without authenticating.
What Is It
CVE-2026-78401 is a deserialization-of-untrusted-data weakness (CWE-502) affecting IBM's access management products. According to the NVD description, IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 "could allow a remote unauthenticated attacker to execute arbitrary code on the system."
IBM PSIRT ([email protected]) reported the vulnerability. NVD published it on 2026-10-08, and its status is currently "Awaiting Analysis."
Why It Matters
IBM's CVSS v3.1 base score is 9.8 (Critical), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In plain terms:
- Network-reachable: attackers can trigger it remotely.
- Low complexity: no special conditions are needed.
- No privileges or user interaction: an attacker needs no credentials and no help from a user.
- High impact on confidentiality, integrity and availability.
These products handle identity and access, so arbitrary code execution on them is serious exposure.
As of this writing, CISA's Known Exploited Vulnerabilities (KEV) catalog has no entry for CVE-2026-78401. That means KEV does not confirm active exploitation at this time.
What's Vulnerable
According to the NVD affected-product data:
| Product | Affected Versions |
|---|---|
| IBM Security Verify Access | 10.0 through 10.0.9.2 |
| IBM Security Verify Access Container | 10.0 through 10.0.9.2 |
| IBM Verify Identity Access | 11.0 through 11.0.3 |
| IBM Verify Identity Access Container | 11.0 through 11.0.3 |
Both the appliance/software and container versions of each product line are listed as affected.
Patch Status
The supplied data does not name fixed versions or specific remediation steps. IBM has published a security bulletin for this vulnerability, linked below. Organizations running affected versions should check that bulletin for fixes or workarounds and treat remediation as a priority, given the critical severity and the fact that no authentication is needed. CISA has not issued a KEV required action, since there is no KEV listing.