Description
IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
Published: 2026-09-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (CWE‑79)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw (CWE‑79) affecting IBM Verify Identity Access, IBM Verify Identity Access Container, IBM Security Verify Access, and IBM Security Verify Access Container products. The CVE description lists the affected product series but provides no further technical detail. The primary impact is the potential delivery of malicious scripts to users interacting with the affected components.

Affected Systems

Affected products are IBM Verify Identity Access versions 11.0.0 through 11.0.3 (including the interim fix 001), IBM Verify Identity Access Container versions 11.0.0 through 11.0.3, IBM Security Verify Access versions 10.0.0 through 10.0.9.2 (including the interim fix 001), and IBM Security Verify Access Container versions 10.0.0 through 10.0.9.2.

Risk and Exploitability

The CVSS score is 6.1, indicating moderate severity. The EPSS score is less than 1%, implying a low likelihood of exploitation. The vulnerability is not listed in CISA KEV, so no publicly known exploits exist. Because the CVE description does not provide details on the exploitation path or conditions, the exact attack vector remains unspecified.

Generated by OpenCVE AI on September 20, 2026 at 22:01 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Download and apply IBM Verify Identity Access v11.0.3 Interim Fix 001 from IBM Fix Central (https://www.ibm.com/support/fixcentral/quickorder).
  • Download and apply IBM Security Verify Access v10.0.9.2 Interim Fix 001 from IBM Fix Central (https://www.ibm.com/support/fixcentral/quickorder).
  • Download and apply IBM Verify Identity Access Container interim fix from IBM (https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers).
  • Download and apply IBM Security Verify Access Container interim fix from IBM (https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers).
  • If patch deployment is delayed, isolate the affected systems from untrusted networks to limit exposure.

Generated by OpenCVE AI on September 20, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T14:36:48.221Z

Reserved: 2026-06-24T21:38:43.379Z

Link: CVE-2026-13276

cve-icon Vulnrichment

Updated: 2026-09-15T14:36:05.009Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:01.557

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-13276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')