PatchSiren cyber security CVE debrief
CVE-2026-19491 IBM CVE debrief
IBM Security Verify Access and IBM Verify Identity Access are vulnerable to authentication bypass. A remote attacker could exploit this vulnerability to bypass authentication. Defenders responsible for IBM Security Verify Access and IBM Verify Identity Access deployments should assess exposure and prioritize remediation to prevent potential unauthorized access. The vulnerability affects IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3.
- Vendor
- IBM
- Product
- Security Verify Access
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-10
Who should care
Defenders responsible for IBM Security Verify Access and IBM Verify Identity Access deployments should assess exposure and prioritize remediation.
Why it matters
CVE-2026-19491 is a critical vulnerability in IBM Security Verify Access and IBM Verify Identity Access that allows remote attackers to bypass authentication. Defenders responsible for affected deployments should prioritize remediation to prevent potential unauthorized access.
- Remote attackers may bypass authentication mechanisms
- Affected systems may be vulnerable to unauthorized access
- Defenders should verify authentication mechanisms for affected systems
- Remediation priority is high for affected systems
Technical summary
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 are affected by a vulnerability that could allow a remote attacker to bypass authentication due to improper authentication. The vulnerability has a CVSS score of 9.1 and a severity of CRITICAL. Defenders should review and apply IBM patches for affected versions of Security Verify Access and Verify Identity Access.
Defensive priority
High priority remediation is recommended for affected systems.
Recommended defensive actions
- Review and apply IBM patches for affected versions of Security Verify Access and Verify Identity Access
- Verify authentication mechanisms for affected systems
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and source item provide details on the vulnerability. IBM has released a vendor advisory with patch information. The vulnerability allows remote attackers to bypass authentication due to improper authentication in affected versions of IBM Security Verify Access and IBM Verify Identity Access. Defenders should verify authentication mechanisms for affected systems and prioritize remediation. The source item and CVE record provide further details on the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19491 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19491
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19491 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19491
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify A
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19491.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7291628
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.