CVE-2026-1346Disclosure(ibm / security_verify_access)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ibm security_verify_access systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • security_verify_access
  • security_verify_access_container
  • verify_identity_access
  • verify_identity_access_container

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 7 mentions (2026-04-08); latest day: 1
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
security_verify_accesssecurity_verify_access_containerverify_identity_accessverify_identity_access_container

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-04-08: 7Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-08: 3Technical Details · 2026-04-08: 404-0804-17
Signal classification3 categories
Disclosure
337.5%
Patch
337.5%
General
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-087
Disclosure3General1Patch3
2026-04-171
General1
Full discourse8 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos IBM ❗ CVE-2026-4101 ❗ CVE-2026-1346 ❗ CVE-2026-1345 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-ibm-4/ https://t.co/SLpGtRBpi5

    Post summary

    The tweet lists three IBM vulnerability CVEs and directs readers to a CERT website for more information, but provides no further details or actionable content.

    00020120
    6.7K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for IBM Verify Identity Access Container and other products (CVE-2026-1346) https://vuldb.com/vuln/355972

    Post summary

    The text announces the disclosure of CVE-2026-1346 for IBM Verify Identity Access Container, indicating it has increased severity, and directs readers to a vulnerability database link.

    01010104
    2.1K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: A high privilege escalation #vulnerability in #IBM Security Verify Access allows locally authenticated users to escalate privileges to root. #CVE-2026-1346 CVSS(3.1): 9.3. Read the advisory onhttps://www.ibm.com/support/pages/node/7268253 and #Patch #Patch #Patch

    Post summary

    IBM Security Verify Access has a high‑severity privilege escalation vulnerability (CVE‑2026‑1346) with a 9.3 CVSS score, and IBM has issued a patch advisory via the provided link.

    01000229
    7.2K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-1346 — CVSS 9.3/10 █████████░ IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/TAoT9gWq5I

    Post summary

    CVE-2026-1346 is a critical vulnerability affecting IBM Verify Identity Access Container 11.0‑11.0.2 and IBM Security Verify Access Container 10.0‑10.0.9.1, with a CVSS score of 9.3/10; a patch is now available.

    1000034
    16 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1346 📊 Severity: 9.3 🚨 Risk Level: Critical 🧩 Affects: Ibm Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1346 #CVE-2026-1346 #CVE #Critical #Ibm #CyberSecurity #InfoSec https://t.co/kwuFRN1De7

    Post summary

    The tweet announces CVE-2026-1346 as a critical vulnerability affecting IBM, providing only severity information without any details on exploitation, patches, or technical specifics.

    0000039
    123 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-1346 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0… https://www.cve.org/CVERecord?id=CVE-2026-1346

    Post summary

    The text lists affected IBM product versions for CVE-2026-1346 and provides a link to the CVE record, but offers no further technical, exploit, or mitigation details.

    00000116
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1346: CRITICAL] Vulnerabilities in IBM Verify Identity Access and Security Verify Access could allow local users to escalate privileges to root. Upgrade to secure versions promptly.#cve,CVE-2026-1346,#cybersecurity https://cvefind.com/CVE-2026-1346

    Post summary

    The message alerts on CVE‑2026‑1346, a local privilege escalation flaw in IBM Verify Identity Access, and urges users to upgrade to patched versions promptly to mitigate the risk.

    0000035
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1346: Security Vulnerabilities have bee... Local auth to root escalation in IBM's identity stack - classic over-privileged execution turning your access management... https://zerodaysignal.com/vulnerability/CVE-2026-1346 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    IBM’s identity stack has a local‑auth-to‑root escalation vulnerability that enables over‑privileged execution; no PoC, patch, or active exploitation details are provided.

    0000053
    204 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appibmsecurity_verify_access---
Appibmsecurity_verify_access_container---
Appibmverify_identity_access---
Appibmverify_identity_access_container---

Explore more