Description
IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
Published: 2026-09-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Impersonation
Action: Patch
AI Analysis

Impact

IBM Verify Identity Access lacks proper origin validation, allowing a remote attacker to carry out actions on behalf of the victim and potentially launch further attacks. This flaw permits the execution of privileged operations through crafted requests that bypass normal authentication checks, constituting a remote impersonation vulnerability.

Affected Systems

IBM Verify Identity Access (version 11.0.3 interim fix) and IBM Security Verify Access (version 10.0.9.2 interim fix) are affected, as well as their corresponding container editions. The advisory references interim fixes for the base products and their container variants, which are available for download as of the advisory release.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. EPSS score is < 1%, and the vulnerability is not listed in CISA's KEV catalog, suggesting no publicly known exploits at this time. The attack vector is inferred to be remote, likely via HTTP requests wherein the origin header is not validated. While exploitation would require the attacker to send specifically crafted requests, the potential for privilege escalation remains significant if the flaw is leveraged.

Generated by OpenCVE AI on September 20, 2026 at 22:00 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 Container Container Download


OpenCVE Recommended Actions

  • Apply the official interim fix v11.0.3 for IBM Verify Identity Access and v10.0.9.2 for IBM Security Verify Access.
  • Configure the reverse proxy or application gateway, allowing only trusted origins, as an interim control before the fix is applied.
  • Continuously monitor authentication logs for anomalous origin header values and alert on suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-1385
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-20T00:14:41.911Z

Reserved: 2026-06-24T21:27:48.597Z

Link: CVE-2026-13272

cve-icon Vulnrichment

Updated: 2026-09-20T00:14:36.135Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:01.273

Modified: 2026-09-20T01:16:28.087

Link: CVE-2026-13272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses
  • CWE-1385

    Missing Origin Validation in WebSockets