External risk intelligence

IBM Security Verify Access and Verify Identity Access Deserialization Vulnerability Allows Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-78401

IBM Security Verify Access and IBM Verify Identity Access are identity and access management products. These systems are designed to manage user authentication and access, making them typically deployed as public-facing gateways or identity portals that are reachable from the internet to facilitate user login and access management.

Deserialization

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in IBM's Security Verify Access and Verify Identity Access products. The issue involves the handling of untrusted data, which could allow an unauthorized remote attacker to execute arbitrary code. Given the nature of identity and access management systems, which are often exposed externally, this vulnerability could pose a significant risk to the integrity and availability of user authentication and access controls.

  • Insecure data handling allows remote code execution.
  • Critical system exposure impacts access controls.
  • Verify product relevance for potential compromise.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending specially crafted data over the network to a vulnerable IBM Security Verify Access or IBM Verify Identity Access system. This data, when deserialized, could allow the attacker to execute arbitrary code on the compromised system, potentially leading to a full system takeover.

  • Attacker can access the system remotely.
  • Attacker sends untrusted data for deserialization.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated attacker could execute arbitrary code on affected IBM systems when processing untrusted serialized data. This could potentially compromise the confidentiality, integrity, and availability of the system.

  • System code execution.
  • Via network deserialization of untrusted data.
  • System compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

IBM Security Verify Access and IBM Verify Identity Access are critical for managing user authentication and access. Given their role as potential public-facing gateways, the immediate first step is to identify all instances of the affected technology, confirm their reachability and business criticality, and then assign ownership for remediation planning based on the identified risk.

  • Ownership: Identity and Access Management (IAM) or Infrastructure teams.
  • Verify first: Confirm deployment reachability and business criticality.
  • Action: Plan targeted vendor coordination and remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is IBM Security Verify Access and IBM Verify Identity Access?

These products are enterprise-level identity and access management (IAM) solutions. They function as centralized gateways that govern how users authenticate and access protected applications and network resources. By acting as a gatekeeper, they handle the secure handshake between users and the infrastructure, often serving as the primary portal for sign-on requests and session management across an organization.

What does deserialization of untrusted data mean for CVE-2026-78401?

This refers to a software weakness known as Deserialization of Untrusted Data (CWE-502). In plain terms, the software takes data sent from an outside source and converts it back into an object to use it. If the software trusts this incoming data without verifying it, an attacker can craft malicious data that tricks the system into executing unauthorized commands. In this CVE, the vulnerability allows that malicious code to run on the system, potentially granting an attacker full control.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending specially prepared, untrusted data to the affected IBM systems over the network. Because the system is designed to process incoming data streams automatically, it can be manipulated into executing malicious instructions during the conversion process. It is important to note that the attacker does not need any valid login credentials or prior access to the system to initiate this exploit.

Is my system at risk if it is not exposed to the internet?

Halo Surface Signal notes that because these products manage identities, they are frequently deployed as public-facing gateways or portals reachable from the internet to handle remote user logins. If your instance is internet-facing, it faces a higher direct risk of remote exploitation. However, even systems located within an internal network may be at risk if an attacker has already gained a foothold elsewhere in your infrastructure and can reach the IAM gateway.

What should I do if I am running these IBM products?

Start by identifying every instance of these products within your environment. Verify where each system is deployed—specifically if it is reachable from the internet or restricted to internal traffic—and determine its business criticality. Once mapped, identify the teams responsible for these systems, such as IAM or infrastructure groups, to coordinate and plan your remediation steps according to your organization's security procedures.

References