CVE-2026-78401: IBM Verify Access Unauthenticated RCE via Deserialization [Critical · CVSS 9.8]
CVE-2026-78401
CVSS 9.8
CRITICAL
Unauthenticated remote code execution via unsafe deserialization in IBM Security Verify Access and Verify Identity Access. No workaround, patch now.
Quick Summary
CVE-2026-78401 is a deserialization of untrusted data flaw (CWE-502) that lets a remote, unauthenticated attacker execute arbitrary code on the appliance. Anyone running IBM Security Verify Access 10.0 through 10.0.9.2 or IBM Verify Identity Access 11.0 through 11.0.3 (including container editions) is affected. IBM lists no workaround: upgrade to the fixed releases.
Technical Details
The flaw is a classic untrusted-deserialization bug: the product deserializes attacker-controlled data without sufficient validation, and a crafted payload leads to code execution on the system. IBM’s advisory does not publish the vulnerable endpoint or exploit mechanics, and I won’t guess at them. The same IBM bulletin covers a second unauthenticated deserialization flaw in Verify Identity Access, so treat the whole bulletin as one patch event.
Impact Assessment
Arbitrary code execution with no credentials.
Verify Access sits in front of applications as an access gateway, so a compromised node is a strong pivot point and a candidate for session and credential exposure.
Attackers gain a trusted internal foothold, often with reach into backend app networks.
Microsoft Sentinel KQL Detection Query
No public indicators exist yet, so this is behavioral: it flags shells, downloaders or interpreters spawned by the Verify Access/WebSEAL/Java processes, plus unexpected outbound connections from those hosts. Adjust the host list to your appliances (requires process telemetry from MDE for Linux or equivalent).
// CVE-2026-78401 - suspicious child processes on IBM Verify Access hosts
let lookback = 24h;
// TODO: replace with your Verify Access / Verify Identity Access hostnames
let isvaHosts = dynamic(["isva-prod-01","isva-prod-02","viag-dmz-01"]);
let parentProcs = dynamic(["java","webseald","pdweb","isva"]);
let badChildren = dynamic(["sh","bash","dash","curl","wget","nc","ncat","python","python3","perl","socat"]);
DeviceProcessEvents
| where Timestamp > ago(lookback)
| where DeviceName has_any (isvaHosts) // scope to the appliances
| where InitiatingProcessFileName in~ (parentProcs) // web/Java parent
| where FileName in~ (badChildren) // shell or downloader child
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine,
InitiatingProcessFileName, InitiatingProcessCommandLine
| join kind=leftouter (
DeviceNetworkEvents
| where Timestamp > ago(lookback) and ActionType == "ConnectionSuccess"
| where RemoteIPType == "Public" // outbound to internet
| project DeviceName, NetTime=Timestamp, RemoteIP, RemotePort, InitiatingProcessFileName
) on DeviceName, InitiatingProcessFileName
| where isempty(NetTime) or abs(NetTime - Timestamp) < 10m
| order by Timestamp desc
Validate in a test window first (legitimate admin scripts will trigger it), then promote to an analytics rule with entity mapping on Host and Account.
Mitigation & Recommendations
- Patch: upgrade Verify Identity Access to 11.0.3.1 (fix 11.0.3-ISS-IVIA-FP0001) and Security Verify Access to 10.0.9.3 (fix 10.0.9-ISS-ISVA-FP0003). For containers, use the container download page linked in the IBM bulletin.
- No workaround: IBM lists none. Until patched, restrict network access to management and reverse-proxy interfaces to the minimum required.
- Hunt back: run the query above over the last 30 days where telemetry allows, since exposure may predate disclosure on 2026-10-08.
- Assume-breach check: if a host looks suspicious, rotate secrets and keys stored on the appliance and review issued sessions.
- Validate: after patching, confirm the version, re-run the detection and keep the analytics rule enabled.
References
By Sujit Mahakhud, Microsoft Sentinel specialist.
