CVE-2026-13267CWE-302

CVE-2026-13267

High · published August 13, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
16.0
In the wild
Unconfirmed
What it is

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00248 · 16.0th percentile
Weakness
CWE-302 · Authentication Bypass by Assumed-Immutable Data
Published
2026-08-13T00:17Z
Affected products (4)
ProductVersionsFixed in
ibm/security_verify_access≥ 10.0.0, ≤ 10.0.9.2
ibm/security_verify_accessall versions
ibm/verify_identity_access≥ 11.0, ≤ 11.0.3
ibm/verify_identity_access_container≥ 11.0.0.0, ≤ 11.0.3.0
References (1)
EPSS history
Timeline
  • 12 AUG 19:58Z
    Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
    cvelistv5