PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78399 IBM CVE debrief

IBM Security Verify Access and IBM Verify Identity Access are vulnerable to a denial of service attack due to improper allocation of system resources. An authenticated user could exploit this vulnerability using a specially crafted HTTP query. The vulnerability exists in IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. This medium-severity vulnerability could allow an authenticated user to cause a denial of service. Administrators and security teams should assess exposure, apply patches or mitigations, and verify system resource allocation to prevent exploitation.

Vendor
IBM
Product
Security Verify Access
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Administrators and security teams responsible for IBM Security Verify Access and IBM Verify Identity Access deployments should assess exposure and apply patches or mitigations as needed.

Why it matters

CVE-2026-78399 is a medium-severity vulnerability in IBM Security Verify Access and IBM Verify Identity Access that could allow an authenticated user to cause a denial of service. Administrators and security teams should assess exposure, apply patches or mitigations, and verify system resource allocation to prevent exploitation.

  • Denial of service attacks against authentication and access control systems could lead to service disruptions
  • Verification of system resource allocation and usage is necessary to prevent exploitation
  • Patching affected systems is required to prevent exploitation

Technical summary

The vulnerability exists in IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. An authenticated user could cause a denial of service using a specially crafted HTTP query due to improper allocation of system resources.

Defensive priority

Medium priority for authentication and access control systems

Recommended defensive actions

  • Review and apply IBM's patch for the affected products
  • Monitor authentication and access control systems for unusual activity
  • Verify system resource allocation and usage

Evidence notes

The CVE Program and NVD provide official records of the vulnerability. IBM has released a vendor advisory with patch information. The vulnerability was publicly disclosed on 2026-10-08T21:03:12.965Z. Affected products include IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. Defenders should verify system resource allocation and usage, review and apply IBM's patch for the affected products, and monitor authentication and access control

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78399 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78399

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78399 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78399

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.