Description
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A remote attacker can trigger a denial of service in IBM Verify Identity Access and IBM Security Verify Access by sending requests containing resource references that are not properly validated. The flaw causes the application to consume excessive resources or abort normal processing, interrupting service for legitimate users. This indicates that insufficient validation or checking of input can lead to a denial of services.

Affected Systems

The issue affects IBM Verify Identity Access and IBM Verify Identity Access Container for all releases up through version 11.0.2 and earlier, with the interim patch 11.0.3 IF2 addressing the flaw. IBM Security Verify Access and its Container are affected for all releases prior to version 10.0.9.2, with the interim patch 10.0.9.2 IF2 providing the fix. The affected CPEs correspond to security_verify_access 10.x and 11.x, and their respective container variants.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability, while the EPSS score of <1% reflects a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The attack vector is remote, requiring only network access to the Verify Access services; no local privileges are needed. Successful exploitation would result in service disruption for all users of the affected applications.

Generated by OpenCVE AI on September 20, 2026 at 22:56 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Download and install IBM Verify Identity Access v11.0.3 IF2 from the IBM support site to resolve the validation flaw.
  • Download 10.0.9.2 IF2 from the IBM support site to patch the denial of service, update the image using IBM’s container update guidance at https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers to ensure all patches are included.
  • If upgrading immediately is not possible, restrict inbound traffic to the Verify Access services and employ a Web Application Firewall or load‑balancer rule to block requests that contain malformed or unexpected resource references.

Generated by OpenCVE AI on September 20, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-770
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T19:29:32.128Z

Reserved: 2026-06-24T20:49:13.723Z

Link: CVE-2026-13260

cve-icon Vulnrichment

Updated: 2026-09-15T19:29:19.361Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:01.147

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-13260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling