Overview
IBM has disclosed CVE-2026-16823, a critical improper-authentication vulnerability (CVSS 9.1) affecting IBM Security Verify Access (the product formerly known as IBM Security Access Manager) and its rebranded successor, IBM Verify Identity Access. Both products function as enterprise identity and access-management platforms with a WebSEAL-style reverse proxy that fronts web applications and enforces authentication and authorization policy before traffic reaches backend resources.
According to the NVD advisory, the flaw "could allow a remote attacker to bypass security restrictions due to improper authentication." Because the access-control proxy is the single enforcement point for every protected application behind it, a successful bypass can expose an organization's entire web application portfolio to unauthenticated access. The vulnerability was published on 2026-10-08 and carries the CWE classification CWE-287 (Improper Authentication).
The flaw is part of a broader IBM security bulletin addressing 23 vulnerabilities across the Verify Access/Identity Access product line, including several other authentication-related issues (CVE-2026-19491, CVE-2026-19494) and a separate unauthenticated remote-code-execution flaw via deserialization of untrusted data (CVE-2026-78401). This advisory covers CVE-2026-16823 specifically.
Technical Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-16823 |
| Severity | Critical (CVSS 9.1) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| Attack Vector | Network |
| Attack Complexity | Low |
| Authentication | None required |
| User Interaction | None |
| Scope | Unchanged |
| Impact | Confidentiality: High, Integrity: High, Availability: None |
| Affected Versions | IBM Security Verify Access 10.0 through 10.0.9.2 (incl. Container); IBM Verify Identity Access 11.0 through 11.0.3 (incl. Container) |
| Fixed Versions | IBM Security Verify Access 10.0.9.3 and later; IBM Verify Identity Access 11.0.3.1 and later |
| Assigned By / Vendor | IBM |
| Disclosed | 2026-10-08 |
How It Works
IBM's own bulletin for CVE-2026-16823 does not go materially beyond the summary captured by NVD: a remote attacker can bypass security restrictions "due to improper authentication," classified under CWE-287. IBM has not published a deeper root-cause writeup (e.g., the specific endpoint, header, or module involved) in its public bulletin at the time of this advisory — we are stating that plainly rather than speculating about internal mechanics IBM has not confirmed.
What can be said with confidence, based on the product architecture and the CVSS vector, is the shape of the risk:
The role of the access-control proxy
IBM Security Verify Access / Verify Identity Access sit in front of protected applications as a reverse proxy, deciding on every request whether a client has presented valid credentials and whether its session is entitled to reach the requested resource. This single point of enforcement is what makes the product valuable — and what makes an authentication-bypass flaw in it so severe. Any logic error that lets a request skip, confuse, or short-circuit that enforcement step effectively unlocks everything the proxy was protecting.
Why the CVSS vector matters
The vector — AV:N/AC:L/PR:N/UI:N — means the flaw is exploitable remotely over the network, requires low attack complexity, needs no prior privileges, and needs no victim interaction. Combined with C:H/I:H, a successful bypass gives an attacker high-confidentiality and high-integrity impact: read and potentially modify access to whatever the proxy was gatekeeping, without ever supplying valid credentials.
General risk pattern for WebSEAL-style bypasses
In access-control reverse proxies of this type, authentication-bypass bugs typically trace back to one of a few recurring patterns: inconsistent policy enforcement between different endpoint types (e.g., REST APIs vs. browser-facing junctions), request normalization differences between the proxy and the backend it protects, or session/token validation logic that can be satisfied with a malformed or replayed credential. We flag these as general categories relevant to this product family — not as a confirmed root cause for CVE-2026-16823, since IBM has not published that level of detail.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | High — unauthenticated access to resources the proxy was meant to protect |
| Integrity | High — potential for unauthorized actions performed under the guise of a bypassed session |
| Availability | None — the flaw itself does not impact uptime, per the CVSS vector |
| Scope of exposure | Every application or service fronted by a vulnerable Verify Access / Identity Access deployment |
| Business impact | Loss of the primary SSO/access-control boundary for enterprise web applications |
Who Is At Risk
Organizations using IBM Security Verify Access or IBM Verify Identity Access as their web access-control, reverse-proxy, or single-sign-on front door are at risk — particularly deployments still on 10.0 through 10.0.9.2 or 11.0 through 11.0.3 that have not applied the fix. Because these platforms are commonly deployed at the perimeter of internal and customer-facing applications in large enterprises, financial institutions, and government environments, the practical blast radius extends to every backend application that relies on the proxy for authentication.
Potential Attack Chain
- Attacker identifies an internet-facing or partner-facing Verify Access / Identity Access reverse-proxy junction.
- Attacker crafts a request designed to trigger the improper-authentication condition, bypassing the proxy's normal credential checks.
- The proxy forwards the request to the backend application as if it originated from an authenticated, authorized session.
- Attacker gains unauthorized access to protected resources — potentially including administrative interfaces, internal applications, or sensitive data — without ever presenting valid credentials.
- Depending on what the bypassed application exposes, the attacker pivots further (data exfiltration, lateral movement, or chaining with one of the other 22 vulnerabilities in the same bulletin, such as the authenticated code-execution issue CVE-2026-16916).
Mitigation
Immediate Actions
- Upgrade without delay. IBM has shipped fixed releases: IBM Security Verify Access 10.0.9.3 and IBM Verify Identity Access 11.0.3.1. Apply the appropriate fix pack to every affected appliance and container deployment.
- Inventory all deployments, including Container editions, which are listed separately in IBM's affected-versions matrix — don't assume a container deployment inherited a host-level patch.
- Review IBM's official bulletin (linked below) directly for the exact fix-pack download, interim fix, or APAR identifier applicable to your specific version before upgrading, since IBM may publish additional guidance after this advisory's publication date.
- If immediate patching isn't feasible, consult IBM support for any available interim fix or configuration-based mitigation specific to your deployed version.
Detection Opportunities
- Review WebSEAL/reverse-proxy access logs for requests that reached backend applications without a corresponding successful authentication event in the proxy's session logs.
- Audit for anomalous access patterns to applications normally gated behind Verify Access junctions — particularly admin consoles, internal APIs, and sensitive data endpoints.
- Cross-reference authentication logs against backend application logs; discrepancies (backend activity with no matching proxy-side login) are a strong indicator of attempted or successful exploitation.
- Monitor for unusual or malformed requests to known Verify Access endpoints following public disclosure, as scanning activity typically increases after a CVSS 9.1 bulletin is published.
Defence-in-Depth
- Apply network segmentation so that even a bypassed proxy session cannot reach management interfaces or sensitive backend systems directly.
- Enforce additional authentication at the application layer where feasible, rather than relying solely on the reverse proxy as the only control.
- Keep Verify Access / Identity Access patched on a regular cadence going forward — this bulletin ships alongside 22 other fixes, underscoring the value of timely update cycles for perimeter identity infrastructure.
- Maintain a tested incident-response plan for identity-infrastructure compromise, given the scale of access a bypass of this kind can grant.
Discovery & Disclosure
- Published: 2026-10-08 (NVD); CVE reserved 2026-07-24.
- CISA KEV status: Not listed on the CISA Known Exploited Vulnerabilities catalog as of this advisory's publication. This advisory will be updated if that changes.
- Proof-of-concept status: No public proof-of-concept exploit code has been identified at the time of writing, and no confirmed in-the-wild exploitation has been reported.
- Vendor: IBM, as part of a combined bulletin covering 23 vulnerabilities in IBM Security Verify Access and IBM Verify Identity Access.