CVE-2026-12358
Received Received - Intake

IBM Verify Identity Access Denial of Service

Vulnerability report for CVE-2026-12358, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: IBM Corporation

Description

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Verify Identity Access is vulnerable to a denial of service attack due to insufficient validation of incoming request resources. This means a remote attacker could exploit this flaw to disrupt the availability of the service.

Impact Analysis

This vulnerability could allow an attacker to make the IBM Verify Identity Access service unavailable, potentially disrupting authentication and identity management processes for users and systems relying on it.

Compliance Impact

The vulnerability could lead to a denial of service, potentially disrupting access to critical systems. This may impact compliance with standards requiring availability, such as GDPR (data processing integrity) or HIPAA (system availability for protected health information). However, specific compliance impacts are not detailed in the provided CVE information.

Mitigation Strategies

Apply the latest security patches from IBM for IBM Verify Identity Access to address insufficient validation of incoming request resources. Monitor IBM's security advisories for updates and ensure network traffic is filtered to prevent excessive resource consumption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12358. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart