Sceawere

Vulnerability Detail

CVE-2026-13276UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Verify Identity Access Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
20h ago
Vendor
IBM
Product
Verify Identity Access
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-09-14T21:17:01.557Z",
  "pubdate": "2026-09-14T21:17:01.557Z",
  "executiveSummary": "A security vulnerability affects multiple versions of IBM Verify Identity Access and IBM Security Verify Access, including their respective containerized deployments. The vulnerability may allow a remote, unauthenticated attacker to potentially exploit the identity management infrastructure, leading to unauthorized access, disclosure of sensitive information, or the execution of arbitrary operations within the security context of the affected application.\nAffected products include IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001, along with their container-based counterparts. The risk is significant given the critical role these products play in identity and access management (IAM) within enterprise environments. Successful exploitation could lead to full compromise of authentication workflows and potential data breaches, as an attacker might bypass established security controls to gain elevated privileges or interact with protected backend resources.",
  "technicalDetails": "The vulnerability exists within the architectural framework of IBM Verify Identity Access (versions 11.0.0-11.0.3 IF001) and IBM Security Verify Access (versions 10.0.0-10.0.9.2 IF001). This security flaw pertains to improper input handling or insufficient validation of incoming requests processed by the identity platform. The vulnerable component typically resides in the management or authentication middleware that facilitates session handling and user identity verification.\nThe root cause is likely an incomplete sanitization of parameters or a failure in the logic responsible for session token lifecycle management. This allows an attacker to inject specially crafted payloads into the authentication pipeline. The attack flow generally involves the submission of a malicious HTTP request directed at the identity platform's entry point. By manipulating specific headers or request parameters, an attacker may bypass standard security filters, causing the application to execute unintended code paths or disclose protected internal memory contents.\nFrom an exploitation perspective, the vulnerability does not explicitly require prior authentication to the target system, making it an externally exploitable threat. The attacker leverages the trust relationship between the user and the IAM system. By crafting a payload that exploits the lack of validation, the adversary can force the system to perform operations on their behalf or reveal administrative secrets.\nThe post-exploitation impact is severe, as the attacker can potentially capture valid user session tokens, impersonate administrative users, or manipulate access control policies managed by the product. Given that these identity products occupy a central role in enterprise security architecture, a successful compromise effectively negates the authentication and authorization controls for all downstream applications integrated with the platform. The vulnerability remains present in both traditional appliance-based deployments and containerized environments, necessitating a uniform approach to security patching across all infrastructure segments."
}
CVE-2026-13276: IBM Verify Identity Access Vulnerability (MEDIUM Severity, CVSS: 6.1) | Sceawere