
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8861 is an information disclosure vulnerability in IBM Security Verify Access and IBM Verify Identity Access caused by the generation of detailed technical error messages returned in the browser. A remote, unauthenticated attacker can leverage the exposed information to conduct further attacks against the system. Affected products and versions include IBM Security Verify Access 10.0 through 10.0.9.1, IBM Verify Identity Access 11.0 through 11.0.2, and their respective container variants. The vulnerability was published on July 17, 2026, with an IBM advisory released on July 8, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (IBM Advisory, GitHub Advisory).
The root cause is classified as CWE-209 (Generation of Error Message Containing Sensitive Information), where the application returns overly verbose technical error messages to the browser without sanitizing or suppressing sensitive details. An unauthenticated remote attacker can trigger these error conditions via crafted network requests — no privileges or user interaction are required. The disclosed information (e.g., stack traces, internal paths, configuration details) can be used to map the application's internals and inform subsequent, more targeted attacks (IBM Advisory, GitHub Advisory).
Successful exploitation results in a low-level confidentiality impact: sensitive technical information about the system's environment, configuration, or internal state is exposed to unauthenticated remote attackers. There is no direct integrity or availability impact. However, the disclosed information can serve as reconnaissance data to facilitate more severe follow-on attacks against the IBM Security Verify infrastructure (IBM Advisory, GitHub Advisory).
IBM has released patches addressing this vulnerability; users should upgrade IBM Security Verify Access to a version beyond 10.0.9.1 and IBM Verify Identity Access (and their container variants) to a version beyond 11.0.2. As a general workaround, administrators should configure the application to suppress detailed technical error messages from being returned to end users, replacing them with generic error pages. Refer to the IBM support advisory for specific fix pack details and upgrade instructions (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."