
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4938 is an incorrect authorization vulnerability in IBM Verify Identity Access and IBM Security Verify Access that allows an attacker with read-only privileges to make unauthorized modifications and deployments outside of their assigned permissions. The vulnerability affects IBM Verify Identity Access 11.0 through 11.0.2, IBM Security Verify Access 10.0 through 10.0.9.1, and their respective container variants across the same version ranges. It was published on July 17, 2026, with an IBM advisory released on July 8, 2026. The CVSS v3.1 base score is 6.5 (Medium) (IBM Advisory, GitHub Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization), meaning the product performs an authorization check when an actor attempts to access a resource or perform an action, but does not correctly enforce the check. An attacker with low-privileged (read-only) network access can exploit this flaw to bypass access controls and perform write operations — including configuration modifications and deployments — that should be restricted to higher-privileged roles. No user interaction is required, and the attack complexity is low, making exploitation straightforward for any authenticated low-privileged user with network access to the affected system (IBM Advisory, GitHub Advisory).
Successful exploitation allows a low-privileged attacker to make unauthorized modifications and deployments within IBM Verify Identity Access or IBM Security Verify Access environments, resulting in a high integrity impact. Since these products serve as identity and access management platforms, unauthorized configuration changes or deployments could undermine authentication policies, access control rules, and governance controls across the enterprise. Confidentiality and availability are not directly impacted by this vulnerability, but integrity compromise of an IAM platform can have cascading effects on dependent systems and security posture (IBM Advisory, GitHub Advisory).
IBM has released a security advisory addressing this vulnerability and patches are available. Affected users should upgrade IBM Verify Identity Access to a version beyond 11.0.2, IBM Security Verify Access to a version beyond 10.0.9.1, and apply the same guidance to their respective container variants. Organizations should consult the IBM support page for specific fix pack details and apply updates as soon as possible, prioritizing instances exposed to internal networks where low-privileged users may have access (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."