IBM access software flaw lets attackers run code without credentials, hitting versions up to 10.0.9.2 and 11.0.3
A deserialization flaw in IBM access management software lets attackers run arbitrary code without credentials, affecting versions up to 10.0.9.2 and 11.0.3.

Key points
- CVE-2026-78406 carries a CVSS score of 9.8, rated critical.
- The flaw allows unauthenticated remote code execution via untrusted data deserialization.
- IBM Security Verify Access and Verify Identity Access versions up to 10.0.9.2 and 11.0.3 are affected.
Security teams managing IBM identity access solutions face a severe exposure following the disclosure of a critical vulnerability. The flaw, tracked as CVE-2026-78406, enables remote attackers to execute arbitrary code on affected systems without requiring authentication. The issue stems from the insecure deserialization of untrusted data, a weakness classified under CWE-502.
How it unfolded
- The vulnerability was assigned CVE-2026-78406 and recorded in the National Vulnerability Database.
- Analysts determined the root cause is the deserialization of untrusted data within the application logic.
- IBM confirmed that versions of Security Verify Access up to 10.0.9.2 and Verify Identity Access up to 11.0.3 are vulnerable.
Who is affected
Organisations deploying IBM Security Verify Access are at risk if they are running version 10.0 through 10.0.9.2. Similarly, those using IBM Verify Identity Access versions 11.0 through 11.0.3 are exposed. The vulnerability also impacts the containerised variants of these products, specifically IBM Security Verify Access Container up to 10.0.9.2 and IBM Verify Identity Access Container up to 11.0.3. Because the attack vector is remote and requires no authentication, any instance exposed to untrusted networks is potentially accessible to threat actors.
The fix
No patch or security update has been confirmed in the source material. Administrators should monitor official IBM security advisories for the release of remediation packages. Until a fix is provided, exposure remains high for any system running the affected versions. Organisations should assess their current deployment versions against the affected ranges listed in the CVE record. If systems are found to be within the vulnerable range, immediate isolation or compensating controls may be necessary to mitigate the risk of remote code execution.
Background: Threat actors
A threat actor is any entity that initiates a cyber attack. They range from automated software to organised criminal groups. Understanding their motive helps you predict their behaviour. Most are not after you specifically but exploit common weaknesses for quick financial gain.
Read the full guide: Threat Actors Explained: Motives, Methods and Misconceptions
What to do and how to stay safe: IBM
- Audit your environment to identify any instances of IBM Security Verify Access or Verify Identity Access running versions 10.0.9.2 or lower, and 11.0.3 or lower.
- Restrict network access to these services so that only trusted internal hosts can reach the management interfaces, reducing the attack surface for unauthenticated remote attempts.
- Monitor server logs and network traffic for unusual deserialization activity or unexpected outbound connections that may indicate exploitation attempts.
- Prepare to apply the vendor’s update once IBM releases a patch, testing it in a non-production environment first to ensure stability.
Step-by-step guide: Patch Management: Eight Questions Answered for Stability
General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is the severity of CVE-2026-78406?
The vulnerability has a CVSS score of 9.8, which is rated as critical.
Which IBM products are affected by this flaw?
IBM Security Verify Access up to 10.0.9.2, IBM Verify Identity Access up to 11.0.3, and their respective container versions are affected.
Does an attacker need credentials to exploit this?
No, the vulnerability allows a remote unauthenticated attacker to execute arbitrary code.



