CVE-2026-12359
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation

Overview

CVE-2026-12359 is an authentication bypass vulnerability in IBM Security Verify Access and IBM Verify Identity Access products caused by an inconsistent interpretation of HTTP requests by a reverse proxy. It affects IBM Security Verify Access versions 10.0 through 10.0.9.2 (including the container variant), IBM Verify Identity Access versions 11.0 through 11.0.3, and IBM Verify Identity Access Container versions 11.0 through 11.0.3. The vulnerability was published on August 12, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 8.1 (High) (Github Advisory, IBM Advisory).

Technical details

The root cause is classified as CWE-287 (Improper Authentication), arising from an inconsistent interpretation of HTTP requests between the reverse proxy and backend servers — a class of vulnerability commonly associated with HTTP request smuggling. When the reverse proxy and backend server disagree on how to parse HTTP request boundaries or headers (e.g., conflicting Content-Length and Transfer-Encoding headers), an attacker can craft requests that bypass authentication controls enforced at the proxy layer. Exploitation requires no privileges and no user interaction, though attack complexity is rated High, indicating that specific conditions or precise request crafting are necessary (Github Advisory, IBM Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to access sensitive information and potentially modify data by bypassing authentication controls enforced by the reverse proxy. The CVSS scoring reflects high impacts across confidentiality, integrity, and availability, suggesting that a successful attack could result in unauthorized data access, data manipulation, and potential disruption of identity and access management services. Given that the affected products are identity and access management platforms, compromise could expose authentication tokens, user credentials, and session data, and may facilitate lateral movement within an enterprise environment (Github Advisory, IBM Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable, consistent with the High attack complexity rating. The EPSS score is approximately 0.324%, placing it in the 25th percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE.

Mitigation and workarounds

IBM has released a patch addressing this vulnerability; affected users should apply the fix referenced in IBM support page node 7283079. Organizations should ensure consistent HTTP request parsing configurations between the reverse proxy and backend servers to eliminate ambiguity that enables request smuggling. As an interim measure, implementing request validation and filtering at the reverse proxy level — particularly rejecting requests with conflicting Content-Length and Transfer-Encoding headers — can reduce exposure. Monitoring for anomalous HTTP requests with ambiguous or conflicting headers is also recommended (IBM Advisory).

Community reactions

Coverage of CVE-2026-12359 has been limited to automated vulnerability tracking platforms and social media aggregators such as VulnDB, RedPacketSecurity on Mastodon, and CyberHub on Bluesky, with no notable independent researcher commentary or significant media coverage identified at this time.

Additional resources


SourceThis report was generated using AI

Related IBM Security Verify Access (formerly ISAM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17616CRITICAL9.8
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026
CVE-2026-13267HIGH8.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026
CVE-2026-12359HIGH8.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026
CVE-2026-11932HIGH7.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026
CVE-2026-12618HIGH7.2
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management