CVE-2026-78406 is a critical (CVSS 9.8) deserialization flaw in IBM Security Verify Access and IBM Verify Identity Access that could let a remote, unauthenticated attacker execute arbitrary code.
What Is It
CVE-2026-78406 is a deserialization-of-untrusted-data weakness (CWE-502) in IBM's access management products. IBM's PSIRT says a remote attacker without authentication could execute arbitrary code on an affected system.
IBM's PSIRT published the record to NVD on 2026-10-08. NVD lists it as "Awaiting Analysis," which means the scoring below comes from IBM as the CNA. NVD has not published its own assessment yet.
Why It Matters
IBM gives the flaw a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector means:
- Network-reachable: no local access is needed.
- Low attack complexity: no special conditions have to be in place.
- No privileges or user interaction required.
- High impact on confidentiality, integrity and availability.
These products handle access management, so compromising one could expose the authentication layer that sits in front of other applications.
Exploitation status: The supplied CISA KEV data contains no entry for this CVE, so KEV does not confirm active exploitation as of this writing. That can change, and the severity alone makes this a high patching priority.
What's Vulnerable
According to the NVD record, these IBM products are affected:
| Product | Affected Versions |
|---|---|
| IBM Security Verify Access | 10.0 through 10.0.9.2 |
| IBM Security Verify Access Container | 10.0 through 10.0.9.2 |
| IBM Verify Identity Access | 11.0 through 11.0.3 |
| IBM Verify Identity Access Container | 11.0 through 11.0.3 |
Both the appliance/software editions and the container editions are listed.
Patch Status
The NVD record links to an IBM support advisory (node 7291628) but does not list fixed versions or specific remediation steps. CISA has published no required action because there is no KEV entry.
Administrators running any affected version should:
- Review IBM's advisory for fixed releases and mitigation guidance.
- Inventory all Verify Access and Verify Identity Access deployments, including container deployments.
- Prioritize patching internet-facing instances, given the unauthenticated network attack vector.
Sources
- NVD, CVE-2026-78406
- IBM Security Bulletin (node 7291628)
- CISA Known Exploited Vulnerabilities Catalog (no entry for this CVE in the supplied data)