CVE Vulnerabilities

CVE-2025-36356

Execution with Unnecessary Privileges

Published: Oct 06, 2025 | Modified: Dec 15, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required.

Weakness

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Affected Software

NameVendorStart VersionEnd Version
Security_verify_accessIbm10.0.0.0 (including)10.0.9.0 (excluding)
Security_verify_accessIbm10.0.9.0 (including)10.0.9.0 (including)
Security_verify_accessIbm10.0.9.0-interim_fix1 (including)10.0.9.0-interim_fix1 (including)
Security_verify_accessIbm10.0.9.0-interim_fix2 (including)10.0.9.0-interim_fix2 (including)
Security_verify_access_dockerIbm10.0.0.0 (including)10.0.9.0 (excluding)
Security_verify_access_dockerIbm10.0.9.0 (including)10.0.9.0 (including)
Security_verify_access_dockerIbm10.0.9.0-interim_fix1 (including)10.0.9.0-interim_fix1 (including)
Security_verify_access_dockerIbm10.0.9.0-interim_fix2 (including)10.0.9.0-interim_fix2 (including)

Potential Mitigations

References