CVE-2026-12109

high

Description

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an attacker with administrative privileges and access to the local management interface to execute arbitrary code due to an unbounded write to a fixed-size stack buffer.

References

https://www.ibm.com/support/pages/node/7291628

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95265

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-09

Risk Information

CVSS v2

Base Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00197