PatchSiren cyber security CVE debrief
CVE-2026-78388 IBM CVE debrief
IBM Security Verify Access and IBM Verify Identity Access are vulnerable to cross-site request forgery. This CVE was published on 2026-10-08T21:03:04.989Z and has not been modified since then. The vulnerability affects multiple versions of these products, specifically IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. Defenders should prioritize verifying exposure of Security Verify Access and Verify Identity Access deployments, especially those with internet-exposed interfaces.
- Vendor
- IBM
- Product
- Security Verify Access
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Security Verify Access and Verify Identity Access deployments, especially those with internet-exposed interfaces, should assess exposure and prioritize verification.
Why it matters
Defenders should prioritize verifying exposure of Security Verify Access and Verify Identity Access deployments to cross-site request forgery attacks and assess the risk of unauthorized actions.
- Potential for unauthorized actions executed by attackers
- Need for verification of exposure and risk assessment
- Importance of implementing compensating controls and monitoring
Technical summary
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 are vulnerable to cross-site request forgery, which could allow an attacker to execute malicious and unauthorized actions. This vulnerability affects multiple versions of these products and requires defenders to prioritize verifying exposure and assessing risk based on their specific deployments and configurations. The vulnerability class is cross-site request forgery, and defenders should focus on verifying exposure and implementing compensating controls.
Defensive priority
Defenders should prioritize verifying exposure of Security Verify Access and Verify Identity Access deployments, especially those with internet-exposed interfaces.
Recommended defensive actions
- Verify exposure of Security Verify Access and Verify Identity Access deployments
- Assess the risk of cross-site request forgery attacks
- Implement compensating controls to mitigate potential attacks
- Monitor for suspicious activity and update affected systems
- Review vendor patch guidance for Security Verify Access and Verify Identity Access
- Conduct exposure review for internet-exposed interfaces
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and source item provide details on the vulnerability, but additional information from IBM's official advisory is needed for comprehensive risk assessment. The official CVE Program record and NIST NVD detail page offer source-provided CVE metadata and vulnerability assessment. However, defenders need to verify exposure and assess risk based on their specific deployments and configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78388 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78388
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78388 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78388
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify A
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/78xxx/CVE-2026-78388.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7291628
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.