Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
Summary
| CVE | CVE-2026-13272 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-14 21:17:01 UTC |
| Updated | 2026-09-20 01:16:28 UTC |
| Description | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems. |
Risk And Classification
Primary CVSS: v3.1 5.4 MEDIUM from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS: 0.001480000 probability, percentile 0.044060000 (date 2026-09-16)
Problem Types: CWE-1385 | CWE-1385 CWE-1385 Missing Origin Validation in WebSockets
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM | Verify Identity Access | affected 11.0.0 11.0.3 Interim Fix 001 semver | Not specified |
| CNA | IBM | Security Verify Access | affected 10.0.0 10.0.9.2 Interim Fix 001 semver | Not specified |
| CNA | IBM | Verify Identity Access Container | affected 11.0.0 11.0.3 Interim Fix 001 semver | Not specified |
| CNA | IBM | Security Verify Access Container | affected 10.0.0 10.0.9.2 Interim Fix 001 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.ibm.com/support/pages/node/7286188 | [email protected] | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 Container Container Download
There are currently no legacy QID mappings associated with this CVE.