
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11904 is an information disclosure vulnerability affecting IBM Verify Identity Access and IBM Security Verify Access products, classified under CWE-209 (Generation of Error Message Containing Sensitive Information). A remote, unauthenticated attacker can trigger detailed technical error messages returned in the browser, potentially exposing sensitive system information that could facilitate further attacks. Affected products and versions include IBM Verify Identity Access 11.0–11.0.2, IBM Security Verify Access 10.0–10.0.9.1, IBM Verify Identity Access Container 11.0–11.0.2, and IBM Security Verify Access Container 10.0–10.0.9.1. The vulnerability was published on July 30, 2026, with an IBM advisory dated July 8, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (IBM Advisory, GitHub Advisory).
The root cause is classified as CWE-209 — the application generates error messages that include sensitive technical details about its internal environment, configuration, or data, which are then returned to the browser. An unauthenticated remote attacker can exploit this by sending crafted or malformed requests to the affected IBM Verify Identity Access or Security Verify Access endpoints, causing the application to return verbose error responses. No authentication, user interaction, or elevated privileges are required, and the attack complexity is low. The disclosed information could be leveraged to map the application's internal structure, identify further attack surfaces, or support follow-on exploitation (IBM Advisory, GitHub Advisory).
Successful exploitation results in partial confidentiality loss — an attacker can obtain sensitive technical information such as stack traces, internal paths, configuration details, or environment data exposed through error messages. There is no direct integrity or availability impact. While the immediate impact is limited, the disclosed information can be used to plan and execute more targeted attacks against the affected identity and access management infrastructure, potentially enabling privilege escalation or lateral movement in subsequent attack stages (IBM Advisory, GitHub Advisory).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2026-11904. The EPSS score is approximately 0.293% (22nd percentile), indicating a low probability of exploitation within 30 days. The NVD SSVC assessment notes the vulnerability is automatable (no human interaction required) but with only partial technical impact. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, IBM Advisory).
IBM has released patches addressing this vulnerability; organizations should upgrade to a fixed version as recommended in the IBM security advisory (node/7279510). As a general workaround, administrators should configure the application to suppress detailed technical error messages from being returned to end users, replacing them with generic error pages. Network-level controls such as web application firewalls (WAFs) can be configured to detect and block responses containing stack traces or verbose error content. Review and apply IBM's guidance at the official advisory page (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."