OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-78407

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-10-08 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

IBM Security Verify Access and IBM Verify Identity Access versions 10.0 through 11.0.3 are susceptible to cross-site scripting, allowing authenticated users to inject arbitrary JavaScript into the Web UI. This could compromise the integrity of user sessions and potentially lead to credential disclosure. Organizations using these products should prioritize remediation to protect against unauthorized access and data breaches.

CVE
CVE-2026-78407
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%
Java

Original NVD Description

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Related CVEs

Other vulnerabilities affecting the same vendor(s)