
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12359 is an authentication bypass vulnerability in IBM Security Verify Access and IBM Verify Identity Access products caused by an inconsistent interpretation of HTTP requests by a reverse proxy. It affects IBM Security Verify Access versions 10.0 through 10.0.9.2 (including the container variant), IBM Verify Identity Access versions 11.0 through 11.0.3, and IBM Verify Identity Access Container versions 11.0 through 11.0.3. The vulnerability was published on August 12, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 8.1 (High) (Github Advisory, IBM Advisory).
The root cause is classified as CWE-287 (Improper Authentication), arising from an inconsistent interpretation of HTTP requests between the reverse proxy and backend servers — a class of vulnerability commonly associated with HTTP request smuggling. When the reverse proxy and backend server disagree on how to parse HTTP request boundaries or headers (e.g., conflicting Content-Length and Transfer-Encoding headers), an attacker can craft requests that bypass authentication controls enforced at the proxy layer. Exploitation requires no privileges and no user interaction, though attack complexity is rated High, indicating that specific conditions or precise request crafting are necessary (Github Advisory, IBM Advisory).
Successful exploitation allows an unauthenticated remote attacker to access sensitive information and potentially modify data by bypassing authentication controls enforced by the reverse proxy. The CVSS scoring reflects high impacts across confidentiality, integrity, and availability, suggesting that a successful attack could result in unauthorized data access, data manipulation, and potential disruption of identity and access management services. Given that the affected products are identity and access management platforms, compromise could expose authentication tokens, user credentials, and session data, and may facilitate lateral movement within an enterprise environment (Github Advisory, IBM Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable, consistent with the High attack complexity rating. The EPSS score is approximately 0.324%, placing it in the 25th percentile for exploitation likelihood within 30 days. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE.
IBM has released a patch addressing this vulnerability; affected users should apply the fix referenced in IBM support page node 7283079. Organizations should ensure consistent HTTP request parsing configurations between the reverse proxy and backend servers to eliminate ambiguity that enables request smuggling. As an interim measure, implementing request validation and filtering at the reverse proxy level — particularly rejecting requests with conflicting Content-Length and Transfer-Encoding headers — can reduce exposure. Monitoring for anomalous HTTP requests with ambiguous or conflicting headers is also recommended (IBM Advisory).
Coverage of CVE-2026-12359 has been limited to automated vulnerability tracking platforms and social media aggregators such as VulnDB, RedPacketSecurity on Mastodon, and CyberHub on Bluesky, with no notable independent researcher commentary or significant media coverage identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."