CVE-2025-36356
critical · 9.3IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required.
9.3
CVSS
0.2%
EPSS (exploit prob.)
9th
EPSS percentile
2025-10-06
Published
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-250
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | security_verify_access | >= 10.0.0.0, < 10.0.9.0 |
| ibm | security_verify_access | 10.0.9.0 |
| ibm | security_verify_access | 10.0.9.0 |
| ibm | security_verify_access | 10.0.9.0 |
| ibm | security_verify_access_docker | >= 10.0.0.0, < 10.0.9.0 |
| ibm | security_verify_access_docker | 10.0.9.0 |
| ibm | security_verify_access_docker | 10.0.9.0 |
| ibm | security_verify_access_docker | 10.0.9.0 |
| ibm | verify_identity_access | >= 11.0.0.0, < 11.0.1.0 |
| ibm | verify_identity_access | 11.0.1.0 |
| ibm | verify_identity_access_docker | >= 11.0.0.0, < 11.0.1.0 |
| ibm | verify_identity_access_docker | 11.0.1.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-36356