CVE-2026-13267

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.
References
Link Resource
https://www.ibm.com/support/pages/node/7283079 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:security_verify_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix1:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-12 20:17

Updated : 2026-08-17 17:54


NVD link : CVE-2026-13267

Mitre link : CVE-2026-13267

CVE.ORG link : CVE-2026-13267


JSON object : View

Products Affected

ibm

  • security_verify_access
  • verify_identity_access_container
  • verify_identity_access
CWE
CWE-302

Authentication Bypass by Assumed-Immutable Data