PatchSiren cyber security CVE debrief
CVE-2026-78399 IBM CVE debrief
IBM Security Verify Access and IBM Verify Identity Access are vulnerable to a denial of service attack due to improper allocation of system resources. An authenticated user could exploit this vulnerability using a specially crafted HTTP query. The vulnerability exists in IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. This medium-severity vulnerability could allow an authenticated user to cause a denial of service. Administrators and security teams should assess exposure, apply patches or mitigations, and verify system resource allocation to prevent exploitation.
- Vendor
- IBM
- Product
- Security Verify Access
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Administrators and security teams responsible for IBM Security Verify Access and IBM Verify Identity Access deployments should assess exposure and apply patches or mitigations as needed.
Why it matters
CVE-2026-78399 is a medium-severity vulnerability in IBM Security Verify Access and IBM Verify Identity Access that could allow an authenticated user to cause a denial of service. Administrators and security teams should assess exposure, apply patches or mitigations, and verify system resource allocation to prevent exploitation.
- Denial of service attacks against authentication and access control systems could lead to service disruptions
- Verification of system resource allocation and usage is necessary to prevent exploitation
- Patching affected systems is required to prevent exploitation
Technical summary
The vulnerability exists in IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. An authenticated user could cause a denial of service using a specially crafted HTTP query due to improper allocation of system resources.
Defensive priority
Medium priority for authentication and access control systems
Recommended defensive actions
- Review and apply IBM's patch for the affected products
- Monitor authentication and access control systems for unusual activity
- Verify system resource allocation and usage
Evidence notes
The CVE Program and NVD provide official records of the vulnerability. IBM has released a vendor advisory with patch information. The vulnerability was publicly disclosed on 2026-10-08T21:03:12.965Z. Affected products include IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. Defenders should verify system resource allocation and usage, review and apply IBM's patch for the affected products, and monitor authentication and access control
Sources and references
Verified primary and authoritative sources
-
CVE-2026-78399 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-78399
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-78399 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78399
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify A
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/78xxx/CVE-2026-78399.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7291628
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.