Sceawere

Vulnerability Detail

CVE-2026-13267UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Verify Access Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
2h ago
Vendor
IBM
Product
Security Verify Access
Attack Type
CWE-302 Authentication Bypass by Assumed-Immutable Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 could allow an authenticated user to gain privileges of another user via a specially crafted request.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-12T20:17:34.690Z",
  "pubdate": "2026-08-12T20:17:34.690Z",
  "executiveSummary": "A privilege escalation vulnerability affects IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, IBM Verify Identity Access Container 11.0 through 11.0.3, and IBM Security Verify Access Container 10.0 through 10.0.9.2.\nThe vulnerability allows an authenticated user to gain the privileges of another user via a specially crafted request.\nThis flaw exposes the system to unauthorized authorization bypasses, potentially allowing attackers to execute operations with elevated or administrative permissions.\nThe attack requires authentication, meaning the adversary must already possess valid user credentials within the targeted identity and access management system.\nExploitation involves submitting manipulated parameters within requests to subvert access control logic.\nThe business impact includes severe confidentiality, integrity, and availability breaches, as compromised administrative accounts can modify security policies, user directories, and enterprise-wide access credentials.",
  "technicalDetails": "The root cause of the vulnerability stems from improper authorization enforcement and insufficient input validation within request processing logic across the affected IBM Security Verify Access and IBM Verify Identity Access versions.\nThe vulnerable components are responsible for handling user session validation, request parameter mapping, and role-based access control evaluations during transactional workflows.\nAuthentication is a prerequisite for exploitation; the threat actor must establish a valid authenticated session prior to launching the attack.\nThe attack flow commences when an authenticated low-privileged user constructs a specially crafted HTTP request containing manipulated parameters or identifiers intended to target resources or operational contexts belonging to a different, higher-privileged user.\nBecause the underlying application logic fails to rigorously verify whether the authenticated session context correlates directly with the requested security context or identifier, the server incorrectly honors the request.\nThis bypasses intended security boundaries, allowing the payload to execute under the authorization context of the victim user.\nPost-exploitation impact includes unauthorized modification of system configurations, access to sensitive directory data, impersonation of administrative users, and complete compromise of identity management services managed by the vulnerable software deployment.\nNetwork exposure encompasses any interface exposed by the affected deployments that handles authenticated user requests."
}
CVE-2026-13267: IBM Verify Access Privilege Escalation (HIGH Severity, CVSS: 8.1) - Sceawere