Missing Origin Validation in IBM Verify Identity Access Exposes Users to Remote Attacks
CVE-2026-13272

Currently unrated

What is CVE-2026-13272?

IBM Verify Identity Access suffers from a lack of origin validation, enabling a remote attacker to execute operations on behalf of a victim. This oversight could facilitate a series of malicious activities against the compromised systems. Users are advised to apply the latest patches to mitigate the risk associated with this vulnerability.

Affected Version(s)

Security Verify Access 10.0.0 <= 10.0.9.2 Interim Fix 001

Security Verify Access Container 10.0.0 <= 10.0.9.2 Interim Fix 001

Verify Identity Access 11.0.0 <= 11.0.3 Interim Fix 001

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.