Missing Origin Validation in IBM Verify Identity Access Exposes Users to Remote Attacks
CVE-2026-13272
Currently unrated
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 14 September 2026
What is CVE-2026-13272?
IBM Verify Identity Access suffers from a lack of origin validation, enabling a remote attacker to execute operations on behalf of a victim. This oversight could facilitate a series of malicious activities against the compromised systems. Users are advised to apply the latest patches to mitigate the risk associated with this vulnerability.
Affected Version(s)
Security Verify Access 10.0.0 <= 10.0.9.2 Interim Fix 001
Security Verify Access Container 10.0.0 <= 10.0.9.2 Interim Fix 001
Verify Identity Access 11.0.0 <= 11.0.3 Interim Fix 001