OVERVIEW: CVE-2026-1346 is a privilege escalation vulnerability affecting IBM Verify Identity Access and IBM Security Verify Access products across multiple versions (Identity Access Container 11.0-11.0.2, Security Verify Access Container 10.0-10.0.9.1, and their on-premises equivalents). The flaw stems from unnecessary privilege execution, allowing locally authenticated users to escalate their access to root level. SEVERITY: This vulnerability carries a CVSS score of 9.3 (CRITICAL) with a local attack vector requiring no user interaction and low attack complexity. The impact is severe, enabling complete compromise of system confidentiality, integrity, and availability. The attack crosses trust boundaries (CVSS Scope Changed), making it particularly dangerous in shared or multi-tenant environments. EXPLOITATION STATUS: Currently, there is no evidence of active exploitation. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on threat tracking lists. The EPSS score of 0.00006 suggests minimal probability of exploitation in the next 30 days. However, the high CVSS rating warrants immediate patching, particularly for internet-facing or shared systems where multiple users may have local access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, <= 10.0.9.1CPE matchmatch criteria | cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:* | ||
>= 10.0.0.0, <= 10.0.9.1CPE matchmatch criteria | cpe:2.3:a:ibm:security_verify_access_container:*:*:*:*:*:*:*:* | ||
>= 11.0.0.0, <= 11.0.2.0CPE matchmatch criteria | cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:* | ||
>= 11.0.0.0, <= 11.0.2.0CPE matchmatch criteria | cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.3 Mastodon, and 1.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.