CVE-2026-78401: IBM Verify Access Unauthenticated RCE via Deserialization [Critical · CVSS 9.8]

CVE Alert · IBM Security Verify Access

CVE-2026-78401

CVSS 9.8
CRITICAL

Unauthenticated remote code execution via unsafe deserialization in IBM Security Verify Access and Verify Identity Access. No workaround, patch now.

Quick Summary

CVE-2026-78401 is a deserialization of untrusted data flaw (CWE-502) that lets a remote, unauthenticated attacker execute arbitrary code on the appliance. Anyone running IBM Security Verify Access 10.0 through 10.0.9.2 or IBM Verify Identity Access 11.0 through 11.0.3 (including container editions) is affected. IBM lists no workaround: upgrade to the fixed releases.

Technical Details

CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness CWE-502 Deserialization of Untrusted Data
Attack vector / privileges Network, low complexity, no privileges, no user interaction
Affected IBM Security Verify Access 10.0 – 10.0.9.2; IBM Verify Identity Access 11.0 – 11.0.3; both container editions, same ranges
Published 2026-10-08 (NVD status: Awaiting Analysis; CVSS from IBM PSIRT)

The flaw is a classic untrusted-deserialization bug: the product deserializes attacker-controlled data without sufficient validation, and a crafted payload leads to code execution on the system. IBM’s advisory does not publish the vulnerable endpoint or exploit mechanics, and I won’t guess at them. The same IBM bulletin covers a second unauthenticated deserialization flaw in Verify Identity Access, so treat the whole bulletin as one patch event.

Exploitation status: IBM’s bulletin does not state whether exploitation is occurring in the wild. Absence of that statement is not evidence of safety for an unauthenticated network RCE on an access-management gateway.

Impact Assessment

Full appliance compromise
Arbitrary code execution with no credentials.
Identity plane exposure
Verify Access sits in front of applications as an access gateway, so a compromised node is a strong pivot point and a candidate for session and credential exposure.
Lateral movement
Attackers gain a trusted internal foothold, often with reach into backend app networks.

Microsoft Sentinel KQL Detection Query

No public indicators exist yet, so this is behavioral: it flags shells, downloaders or interpreters spawned by the Verify Access/WebSEAL/Java processes, plus unexpected outbound connections from those hosts. Adjust the host list to your appliances (requires process telemetry from MDE for Linux or equivalent).

// CVE-2026-78401 - suspicious child processes on IBM Verify Access hosts
let lookback = 24h;
// TODO: replace with your Verify Access / Verify Identity Access hostnames
let isvaHosts = dynamic(["isva-prod-01","isva-prod-02","viag-dmz-01"]);
let parentProcs = dynamic(["java","webseald","pdweb","isva"]);
let badChildren = dynamic(["sh","bash","dash","curl","wget","nc","ncat","python","python3","perl","socat"]);
DeviceProcessEvents
| where Timestamp > ago(lookback)
| where DeviceName has_any (isvaHosts)            // scope to the appliances
| where InitiatingProcessFileName in~ (parentProcs)  // web/Java parent
| where FileName in~ (badChildren)                 // shell or downloader child
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine,
          InitiatingProcessFileName, InitiatingProcessCommandLine
| join kind=leftouter (
    DeviceNetworkEvents
    | where Timestamp > ago(lookback) and ActionType == "ConnectionSuccess"
    | where RemoteIPType == "Public"                  // outbound to internet
    | project DeviceName, NetTime=Timestamp, RemoteIP, RemotePort, InitiatingProcessFileName
  ) on DeviceName, InitiatingProcessFileName
| where isempty(NetTime) or abs(NetTime - Timestamp) < 10m
| order by Timestamp desc

Validate in a test window first (legitimate admin scripts will trigger it), then promote to an analytics rule with entity mapping on Host and Account.

Mitigation & Recommendations

  1. Patch: upgrade Verify Identity Access to 11.0.3.1 (fix 11.0.3-ISS-IVIA-FP0001) and Security Verify Access to 10.0.9.3 (fix 10.0.9-ISS-ISVA-FP0003). For containers, use the container download page linked in the IBM bulletin.
  2. No workaround: IBM lists none. Until patched, restrict network access to management and reverse-proxy interfaces to the minimum required.
  3. Hunt back: run the query above over the last 30 days where telemetry allows, since exposure may predate disclosure on 2026-10-08.
  4. Assume-breach check: if a host looks suspicious, rotate secrets and keys stored on the appliance and review issued sessions.
  5. Validate: after patching, confirm the version, re-run the detection and keep the analytics rule enabled.

References

By Sujit Mahakhud, Microsoft Sentinel specialist.

Similar Posts

Leave a Reply