{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/verify-identity-access-11.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-11923"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Security Verify Access (10.0)","Verify Identity Access (11.0)","Verify Identity Access Container (11.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has disclosed a security vulnerability affecting IBM Security Verify Access (versions 10.0 through 10.0.9.2) and IBM Verify Identity Access (versions 11.0 through 11.0.3, including the containerized deployment). The issue resides within the Reverse Proxy component, which, under specific configurations, performs insufficient cryptographic validation of user-supplied data. This flaw may allow an attacker to bypass security controls by providing malformed or manipulated data that the proxy incorrectly authenticates or validates. The vulnerability is assigned CVE-2026-11923 and carries a CVSS base score of 7.4, indicating high severity due to the potential impact on authentication and session integrity. Defenders should prioritize auditing reverse proxy configurations and applying available patches provided by IBM to remediate the potential for session hijacking or unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability can result in the bypass of security controls enforced by the IBM Reverse Proxy. This may allow unauthorized users to gain access to protected resources or manipulate authentication flows, potentially leading to unauthorized data access or session persistence by malicious actors within the enterprise environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patches for IBM Security Verify Access 10.0.x and IBM Verify Identity Access 11.0.x provided by IBM to resolve CVE-2026-11923.\u003c/li\u003e\n\u003cli\u003eAudit Reverse Proxy configurations for high-risk deployment settings as specified in IBM security advisories.\u003c/li\u003e\n\u003cli\u003eMonitor webserver and proxy logs for anomalous authentication attempts that bypass expected cryptographic signatures or identity assertions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T20:50:20Z","date_published":"2026-08-12T20:50:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ibm-cryptographic-validation/","summary":"IBM Security Verify Access and IBM Verify Identity Access contain a vulnerability in the Reverse Proxy component involving weak cryptographic validation of user-supplied data.","title":"Cryptographic Validation Vulnerability in IBM Security Verify Access","url":"https://feed.craftedsignal.io/briefs/2026-08-ibm-cryptographic-validation/"}],"language":"en","title":"CraftedSignal Threat Feed - Verify Identity Access (11.0)","version":"https://jsonfeed.org/version/1.1"}