CVE-2026-1342
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation

Overview

CVE-2026-1342 is a script injection vulnerability (CWE-829: Inclusion of Functionality from Untrusted Control Sphere) affecting multiple IBM identity and access management products. It allows a locally authenticated user to execute malicious scripts sourced from outside the application's control sphere. Affected products and versions include: IBM Verify Identity Access Container 11.0–11.0.2, IBM Security Verify Access Container 10.0–10.0.9.1, IBM Verify Identity Access 11.0–11.0.2, and IBM Security Verify Access 10.0–10.0.9.1. The vulnerability was published on April 8, 2026, with a CVSS v3.1 base score of 8.5 (High) per the GitHub Advisory Database, or 7.9 (High) per NVD (GitHub Advisory, IBM Support).

Technical details

The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning the affected IBM products import or execute scripts or functionality from sources outside their intended security boundary. The attack vector is local, requiring low complexity and no user interaction, but does require the attacker to be locally authenticated. The changed scope indicator suggests that successful exploitation can affect components or resources beyond the vulnerable application itself. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, IBM Support).

Impact

Successful exploitation allows a locally authenticated attacker to execute arbitrary malicious scripts outside the application's control boundaries, resulting in high confidentiality impact (unauthorized data access), and low integrity and availability impacts. The changed scope means the vulnerability can affect systems and processes beyond the directly vulnerable IBM Verify Identity Access or Security Verify Access instance, increasing the risk of lateral movement or privilege escalation within the environment (GitHub Advisory, IBM Support).

Mitigation and workarounds

IBM has released patches addressing this vulnerability; administrators should consult the IBM support page for specific fixed versions and update instructions (IBM Support). As interim mitigations, restrict local system access to only trusted and necessary authenticated users on systems running affected IBM Verify Identity Access or Security Verify Access versions. Implement access controls to limit which authenticated users can interact with these applications, and monitor for suspicious or unexpected script execution activity on affected hosts.

Community reactions

The vulnerability received coverage from several cybersecurity news outlets and aggregators, including Cybersecurity News and The Hacker Wire, which reported on IBM identity and access vulnerabilities allowing potential sensitive data exposure (Cybersecurity News). The CISA vulnerability bulletin for the week of April 6, 2026 also referenced this CVE. Community reaction has been limited, consistent with the absence of a public exploit and the local-only attack vector.

Additional resources


SourceThis report was generated using AI

Related IBM Security Verify Access (formerly ISAM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-1346HIGH7.8
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 08, 2026
CVE-2026-4938MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-5926MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 23, 2026
CVE-2026-8861MEDIUM5.3
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-7364LOW3.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management