CVE-2026-1345
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation

Overview

CVE-2026-1345 is an OS command injection vulnerability affecting IBM Verify Identity Access and IBM Security Verify Access products. It allows unauthenticated remote attackers to execute arbitrary commands with lower user privileges due to improper validation of user-supplied input (CWE-78). Affected products include IBM Verify Identity Access Container 11.0–11.0.2, IBM Security Verify Access Container 10.0–10.0.9.1, IBM Verify Identity Access 11.0–11.0.2, and IBM Security Verify Access 10.0–10.0.9.1. The vulnerability was published on April 1, 2026, and carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, IBM Advisory).

Technical details

The root cause is improper neutralization of special elements used in OS commands (CWE-78), classified as OS Command Injection. The vulnerability arises because user-supplied input is incorporated into OS command construction without adequate sanitization or escaping, enabling an attacker to inject shell metacharacters or command delimiters. Exploitation requires no authentication, no user interaction, and no special privileges — only network access to the affected service. Relevant attack patterns include CAPEC-88 (OS Command Injection), CAPEC-15 (Command Delimiters), and CAPEC-6 (Argument Injection) (GitHub Advisory, IBM Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary OS commands on the affected system, though execution occurs under lower (non-root) user privileges. This results in low-level impacts to confidentiality, integrity, and availability — attackers could potentially exfiltrate sensitive identity and access management data, modify system configurations, install malware, or cause service disruption. Given that the affected products are identity and access management platforms, compromise could have downstream effects on authentication infrastructure and protected resources (GitHub Advisory, IBM Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing IBM Verify Identity Access or IBM Security Verify Access instances (versions 10.0–10.0.9.1 or 11.0–11.0.2) using tools such as Shodan or Censys, searching for known service banners or login portals.
  2. Identify injectable endpoint: Probe the application's exposed endpoints or API parameters that accept user-supplied input and may be passed to OS-level command execution functions.
  3. Craft malicious payload: Construct an HTTP request containing OS command injection payloads using shell metacharacters (e.g., ;, |, &&, backticks) appended to a legitimate input value (e.g., value; id or value | whoami).
  4. Submit the request: Send the crafted request to the vulnerable endpoint without any authentication credentials.
  5. Achieve command execution: If the application is vulnerable, the injected command executes on the server under the context of the lower-privileged service account, potentially enabling data exfiltration, reverse shell establishment, or further lateral movement (GitHub Advisory, IBM Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from IBM Verify Identity/Security Verify Access servers to external IPs; unusual HTTP requests to application endpoints containing shell metacharacters (;, |, &&, backticks) in parameter values.
  • Logs: Application or web server access logs showing requests with encoded or plaintext shell command injection strings in input fields; error messages referencing OS command execution failures.
  • Process: Unusual child processes spawned by the IBM Verify Access service process (e.g., /bin/sh, bash, curl, wget, python, nc) that are not part of normal operation.
  • File System: Unexpected files written to directories accessible by the service account, such as web shells, scripts, or downloaded binaries; new cron jobs or scheduled tasks created under the service account.

Mitigation and workarounds

IBM has released patches for all affected product lines; organizations should upgrade to versions beyond the affected ranges (IBM Security Verify Access > 10.0.9.1 and IBM Verify Identity Access > 11.0.2) as soon as possible (IBM Advisory). As an interim measure, implement network segmentation to restrict access to IBM Verify Identity/Security Verify Access management interfaces to trusted networks only. Monitor application and system logs for suspicious command execution patterns and unauthorized access attempts. Refer to the IBM support page for specific fix pack details and installation guidance.

Community reactions

The vulnerability received coverage from several cybersecurity news outlets including GBHackers, CyberSecurityNews, CyberPress, and CyberNoz, with articles highlighting the risk of remote attackers accessing sensitive identity data (GBHackers, CyberSecurityNews). A post on Bluesky from the CyberHub blog also noted the vulnerability shortly after disclosure. Coverage generally emphasized the unauthenticated nature of the attack and the sensitivity of the affected IAM platforms, though no significant researcher controversy or vendor dispute has been reported.

Additional resources


SourceThis report was generated using AI

Related IBM Security Verify Access (formerly ISAM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-1346HIGH7.8
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 08, 2026
CVE-2026-4938MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-5926MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 23, 2026
CVE-2026-8861MEDIUM5.3
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-7364LOW3.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management