CVE-2026-11929
Received Received - Intake

Weak Cryptographic Validation in IBM Security Verify Identity Access Reverse Proxy

Vulnerability report for CVE-2026-11929, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: IBM Corporation

Description

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-327 The product uses a broken or risky cryptographic algorithm or protocol.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. This means the system might not properly verify the integrity or authenticity of data sent by users, potentially allowing tampered or malicious data to be processed.

Impact Analysis

This vulnerability could allow attackers to bypass security controls by sending altered data that the system incorrectly trusts. This might lead to unauthorized access, data breaches, or other malicious activities depending on how the reverse proxy is used in your environment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11929. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart