What is CVE-2026-12359?
A vulnerability due to inconsistent interpretation of HTTP requests by a reverse proxy was discovered in IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access (including Container) 11.0 through 11.0.3. A remote unauthenticated attacker could exploit this to gain access to sensitive information. Applying security updates is recommended.
Azərbaycanca: IBM Security Verify Access (10.0-10.0.9.2) və IBM Verify Identity Access (11.0-11.0.3, konteyner daxil) məhsullarında reverse proxy tərəfindən HTTP sorğusunun qeyri-ardıcıl interpretasiyası nəticəsində həssas məlumatların sızması zəifliyi aşkarlanıb. Uzaqdan autentifikasiya olunmamış şəxs bu zəiflikdən istifadə edərək sistem məlumatlarına icazəsiz giriş əldə edə bilər. Təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: IBM
FAQ2
Which versions of IBM Security Verify Access 10.0 are affected by CVE-2026-12359?
Versions 10.0 through 10.0.9.2 of IBM Security Verify Access are affected by this vulnerability.
What can an attacker gain by exploiting CVE-2026-12359?
A remote unauthenticated attacker can gain unauthorized access to sensitive information by exploiting this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.