External risk intelligence

IBM Verify Access and Identity Access Remote Code Execution via Untrusted Data Deserialization

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-78406

IBM Security Verify Access and IBM Verify Identity Access are identity and access management solutions designed to serve as gateways, identity portals, and authentication providers. By their functional nature, these products are commonly deployed as public-facing services to manage user access and identity, making them highly likely to be exposed to the public internet.

Deserialization

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in specific versions of IBM Security Verify Access and IBM Verify Identity Access products. The issue stems from the deserialization of untrusted data, which could allow a remote, unauthenticated attacker to execute arbitrary code on the affected systems. Given the nature of these identity and access management solutions, they are often deployed as public-facing services, increasing the potential exposure of this vulnerability.

  • Flaw allows remote code execution on identity systems.
  • Critical flaw in public-facing identity and access management.
  • Confirm relevance and exposure for critical identity systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by sending specially crafted data over the network to a vulnerable IBM Security Verify Access or IBM Verify Identity Access system. This data would be improperly deserialized, allowing the attacker to execute arbitrary code with the privileges of the running application, potentially leading to a complete compromise of the system.

  • Network access required.
  • Deserializing untrusted data.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated attacker could execute arbitrary code on the system by sending specially crafted data that is deserialized by IBM Security Verify Access and IBM Verify Identity Access. This could impact the confidentiality, integrity, and availability of the affected system.

  • System code execution.
  • Deserializing untrusted data.
  • Compromise of system integrity and availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects IBM Security Verify Access and IBM Verify Identity Access, typically managed by platform or infrastructure teams responsible for identity and access management services. The immediate first step is to inventory all instances of the affected technology, confirm their external reachability and criticality to business operations, and identify the accountable system owners. Subsequent actions will depend on this initial assessment and risk analysis.

  • Identify, confirm reachability, and ownership.
  • Verify business criticality and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is IBM Security Verify Access?

These products are identity and access management solutions. They act as critical gateways and authentication portals that manage how users sign in and access enterprise resources. Because they verify digital identities, they are essential infrastructure components that often bridge the gap between internal systems and the outside world.

What does CVE-2026-78406 mean by deserialization of untrusted data?

This vulnerability falls under the weakness class of deserialization of untrusted data (CWE-502). In simple terms, the software takes complex data structures sent by a user and converts them back into functional objects. If the system does this without validating the input, a remote attacker can inject malicious instructions that the system then mistakenly executes as its own code.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending specifically crafted network traffic containing malicious data to the system. The software processes this data automatically upon receipt. Crucially, this does not require a user to log in or interact with the system first; the vulnerability is reachable by anyone who can reach the service over the network.

Do I need to worry if my instance is not on the internet?

According to Halo Surface Signal, these identity products are designed to act as gateways, making them very likely to be deployed with public-facing access. However, if your instance is strictly internal, the risk is localized to your private network. You should still assess whether any internal user or compromised system could reach the service, as that would still pose a threat.

What should I do first to address this?

Begin by creating a complete inventory of all instances of the affected software within your environment. Once you have a list, confirm which ones are reachable from the internet and define the business criticality of each. Identifying the system owners for these assets is a necessary next step to coordinate a formal risk analysis and plan your patch strategy.

References