CVE-2026-11929
Received Received - Intake

Weak Cryptographic Validation in IBM Security Verify Identity Access Reverse Proxy

Vulnerability report for CVE-2026-11929, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: IBM Corporation

Description

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-327 The product uses a broken or risky cryptographic algorithm or protocol.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. This means the system might not properly verify the integrity or authenticity of data sent by users, potentially allowing tampered or malicious data to be processed.

Impact Analysis

This vulnerability could allow attackers to bypass security controls by sending altered data that the system incorrectly trusts. This might lead to unauthorized access, data breaches, or other malicious activities depending on how the reverse proxy is used in your environment.

Compliance Impact

This vulnerability may lead to weaker cryptographic validation of user data, potentially exposing sensitive information. This could impact compliance with GDPR (data protection) and HIPAA (healthcare data security) by increasing the risk of unauthorized access or data breaches.

Mitigation Strategies

Update IBM Security Verify Identity Access Reverse Proxy to the latest version to ensure proper cryptographic validation. Review and enforce stronger cryptographic settings in the proxy configuration.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11929. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart