CVE-2026-13267
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation

Overview

CVE-2026-13267 is a privilege escalation vulnerability affecting IBM Security Verify Access, IBM Verify Identity Access, and IBM Verify Identity Access Container. An authenticated user can gain the privileges of another user by sending a specially crafted network request. Affected versions include IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and IBM Verify Identity Access Container 11.0 through 11.0.3. The vulnerability was published on August 12, 2026, with a patch available as of the same date. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, IBM Advisory).

Technical details

The vulnerability is classified under CWE-302 (Authentication Bypass by Assumed-Immutable Data), meaning the authentication scheme relies on data elements that are assumed to be fixed or unmodifiable but can in fact be controlled or manipulated by an attacker (GitHub Advisory). An authenticated low-privileged user can craft a specially formed network request that causes the system to process the request under the identity or privilege context of a different user. The attack requires no user interaction and has low attack complexity, making it straightforward to execute once an attacker has any valid authenticated session. No public proof-of-concept code has been identified at this time (GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to impersonate another user and assume their access rights, resulting in high confidentiality and high integrity impact — including unauthorized access to sensitive data and the ability to perform actions on behalf of the targeted user. Availability is not directly impacted. Given that IBM Security Verify Access and Verify Identity Access are identity and access management platforms, exploitation could expose authentication tokens, user credentials, policy configurations, and other sensitive identity data, potentially enabling further lateral movement within an enterprise environment (GitHub Advisory, IBM Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of publication (GitHub Advisory). The EPSS score is approximately 0.248% (16th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated session, which limits the attack surface compared to unauthenticated vulnerabilities, though the low complexity and no user interaction requirement make it accessible to any authenticated attacker.

Exploitation steps

  1. Obtain Authentication: Acquire valid credentials for any low-privileged account on the target IBM Security Verify Access or Verify Identity Access instance (versions 10.0–10.0.9.2 or 11.0–11.0.3).
  2. Identify Target User: Enumerate or identify a higher-privileged user account whose privileges are desired (e.g., an administrator or another user with access to sensitive resources).
  3. Craft Malicious Request: Construct a specially crafted HTTP request that manipulates data elements assumed to be immutable by the authentication scheme — such as session tokens, user identifiers, or other client-supplied parameters — to reference the target user's identity context.
  4. Submit Request: Send the crafted request to the vulnerable IBM Verify Access endpoint over the network. The system, trusting the manipulated data as legitimate, processes the request under the target user's privilege context.
  5. Achieve Privilege Escalation: Leverage the elevated privileges to access sensitive data, modify configurations, or perform actions authorized only for the impersonated user (GitHub Advisory, IBM Advisory).

Indicators of compromise

  • Logs: Authentication or access logs showing a single authenticated user account accessing resources or endpoints typically associated with a different user account; unexpected privilege-level changes in IBM Verify Access audit logs.
  • Network: Unusual or repeated HTTP requests from a single authenticated session targeting user-management or administrative endpoints with anomalous parameter values (e.g., modified user ID fields or session tokens referencing other users).
  • Behavioral: Authenticated sessions performing actions inconsistent with the account's assigned role or permissions; access to data or administrative functions not previously associated with a given user account.

Mitigation and workarounds

IBM has released patches addressing this vulnerability; organizations should apply the available security updates for IBM Security Verify Access (versions 10.0 through 10.0.9.2) and IBM Verify Identity Access (versions 11.0 through 11.0.3) as detailed in the IBM support advisory (IBM Advisory). As interim measures, restrict network access to IBM Verify Access management interfaces to trusted networks and IP ranges, and implement strong authentication controls to limit the pool of authenticated users. Monitor audit logs for anomalous privilege escalation activity from authenticated accounts.

Additional resources


SourceThis report was generated using AI

Related IBM Security Verify Access (formerly ISAM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17616CRITICAL9.8
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026
CVE-2026-13267HIGH8.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026
CVE-2026-12359HIGH8.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026
CVE-2026-11932HIGH7.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026
CVE-2026-12618HIGH7.2
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management