CVE-2026-8861: Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Security Verify Accessto a version that resolves this vulnerability.Fixed in 10.0.9.2 - Upgrade
Upgrade
IBM Verify Identity Accessto a version that resolves this vulnerability.Fixed in 11.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8861?
The severity of CVE-2026-8861 is medium with a score of 5.3.
What is the impact of CVE-2026-8861?
CVE-2026-8861 can allow a remote attacker to obtain sensitive information through detailed technical error messages.
How do I fix CVE-2026-8861?
To fix CVE-2026-8861, apply the latest security updates and patches provided by IBM for affected products.
Which IBM products are affected by CVE-2026-8861?
CVE-2026-8861 affects IBM Security Verify Identity Access and IBM Security Verify Access.
How can CVE-2026-8861 be exploited?
CVE-2026-8861 can be exploited by an attacker through the retrieval of sensitive information from error messages displayed in the browser.