CVE-2026-13272: IBM Security Verify Access

Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.

IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.

Affected products

  • IBM Security Verify Access
  • IBM Security Verify Access Container
  • IBM Verify Identity Access
  • IBM Verify Identity Access Container

Published 2026-09-14. Last modified 2026-09-20.