External risk intelligence

IBM Verify Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-19491

IBM Security Verify Access and IBM Verify Identity Access are enterprise identity and access management solutions designed to serve as authentication portals. These products are intended to be public-facing by design to manage user access, identity verification, and authentication for external users, making them internet-accessible edge services.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in IBM's access management software could allow unauthorized users to bypass security controls. This issue impacts how user identities are verified, potentially exposing sensitive information or systems. The main concern is confirming if our relevant IBM products are in scope and if they are exposed to the internet.

  • Access controls bypassed by attackers.
  • Critical for verifying identity and access.
  • Confirm exposure of IBM access software.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to an exposed authentication service. This bypasses the normal login process, potentially granting the attacker access to protected resources.

  • Exposed authentication service required.
  • Malicious request triggers bypass.
  • Unauthenticated access to resources.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could bypass authentication when supported by the advisory, potentially granting unauthorized access to sensitive system data or user information. This vulnerability affects IBM Security Verify Access and IBM Verify Identity Access products.

  • System and user data could be exposed.
  • Unauthenticated access may occur remotely.
  • Unauthorized access to protected resources.

Operational Fix

Recommended remediation, mitigation, and detection steps

The criticality of this authentication bypass vulnerability in IBM Security Verify Access and IBM Verify Identity Access necessitates immediate attention from platform and security teams. The first practical step is to conduct a comprehensive inventory of all instances of the affected products, determine their exposure to the internet, and identify their business criticality. Once located and prioritized, accountable owners must be identified to plan and execute remediation efforts.

  • Platform and security teams own remediation.
  • Verify product exposure and business criticality.
  • Plan and coordinate risk-based fixes.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is IBM Security Verify Access and IBM Verify Identity Access?

These are enterprise-grade identity and access management solutions. Organizations use them as a central gateway to manage user logins, verify identities, and control access to applications and data, acting as the front door for secure digital services.

What does CVE-2026-19491 mean for security?

This vulnerability is classified as CWE-287, which refers to improper authentication. In plain terms, it means there is a flaw in how the software validates a user's identity, which could allow someone to bypass the login process and gain access without providing valid credentials.

How does an attacker trigger this authentication bypass?

An attacker triggers this by sending a specially crafted network request to the authentication service. It is important to note that this is not triggered by normal user activity or typical login attempts; it requires the deliberate use of a malicious, manipulated request designed to exploit the logic error in the system.

Is my IBM system at risk according to Halo Surface Signal?

Halo Surface Signal indicates these products are designed to be public-facing to serve external users, making them inherently internet-accessible. Because this vulnerability is remotely exploitable without authentication, any instance exposed to the internet carries a high risk of being targeted by unauthorized actors.

What should I do if I run these IBM products?

Your first step is to locate every instance of the affected software within your infrastructure. Once identified, evaluate their connection to the internet and categorize them by business importance. This inventory will help you and your security team coordinate a risk-based plan to apply the necessary updates.

References