
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1345 is an OS command injection vulnerability affecting IBM Verify Identity Access and IBM Security Verify Access products. It allows unauthenticated remote attackers to execute arbitrary commands with lower user privileges due to improper validation of user-supplied input (CWE-78). Affected products include IBM Verify Identity Access Container 11.0–11.0.2, IBM Security Verify Access Container 10.0–10.0.9.1, IBM Verify Identity Access 11.0–11.0.2, and IBM Security Verify Access 10.0–10.0.9.1. The vulnerability was published on April 1, 2026, and carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, IBM Advisory).
The root cause is improper neutralization of special elements used in OS commands (CWE-78), classified as OS Command Injection. The vulnerability arises because user-supplied input is incorporated into OS command construction without adequate sanitization or escaping, enabling an attacker to inject shell metacharacters or command delimiters. Exploitation requires no authentication, no user interaction, and no special privileges — only network access to the affected service. Relevant attack patterns include CAPEC-88 (OS Command Injection), CAPEC-15 (Command Delimiters), and CAPEC-6 (Argument Injection) (GitHub Advisory, IBM Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary OS commands on the affected system, though execution occurs under lower (non-root) user privileges. This results in low-level impacts to confidentiality, integrity, and availability — attackers could potentially exfiltrate sensitive identity and access management data, modify system configurations, install malware, or cause service disruption. Given that the affected products are identity and access management platforms, compromise could have downstream effects on authentication infrastructure and protected resources (GitHub Advisory, IBM Advisory).
;, |, &&, backticks) appended to a legitimate input value (e.g., value; id or value | whoami).;, |, &&, backticks) in parameter values./bin/sh, bash, curl, wget, python, nc) that are not part of normal operation.IBM has released patches for all affected product lines; organizations should upgrade to versions beyond the affected ranges (IBM Security Verify Access > 10.0.9.1 and IBM Verify Identity Access > 11.0.2) as soon as possible (IBM Advisory). As an interim measure, implement network segmentation to restrict access to IBM Verify Identity/Security Verify Access management interfaces to trusted networks only. Monitor application and system logs for suspicious command execution patterns and unauthorized access attempts. Refer to the IBM support page for specific fix pack details and installation guidance.
The vulnerability received coverage from several cybersecurity news outlets including GBHackers, CyberSecurityNews, CyberPress, and CyberNoz, with articles highlighting the risk of remote attackers accessing sensitive identity data (GBHackers, CyberSecurityNews). A post on Bluesky from the CyberHub blog also noted the vulnerability shortly after disclosure. Coverage generally emphasized the unauthenticated nature of the attack and the sensitivity of the affected IAM platforms, though no significant researcher controversy or vendor dispute has been reported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."