
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13267 is a privilege escalation vulnerability affecting IBM Security Verify Access, IBM Verify Identity Access, and IBM Verify Identity Access Container. An authenticated user can gain the privileges of another user by sending a specially crafted network request. Affected versions include IBM Security Verify Access 10.0 through 10.0.9.2, IBM Verify Identity Access 11.0 through 11.0.3, and IBM Verify Identity Access Container 11.0 through 11.0.3. The vulnerability was published on August 12, 2026, with a patch available as of the same date. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, IBM Advisory).
The vulnerability is classified under CWE-302 (Authentication Bypass by Assumed-Immutable Data), meaning the authentication scheme relies on data elements that are assumed to be fixed or unmodifiable but can in fact be controlled or manipulated by an attacker (GitHub Advisory). An authenticated low-privileged user can craft a specially formed network request that causes the system to process the request under the identity or privilege context of a different user. The attack requires no user interaction and has low attack complexity, making it straightforward to execute once an attacker has any valid authenticated session. No public proof-of-concept code has been identified at this time (GitHub Advisory).
Successful exploitation allows an authenticated attacker to impersonate another user and assume their access rights, resulting in high confidentiality and high integrity impact — including unauthorized access to sensitive data and the ability to perform actions on behalf of the targeted user. Availability is not directly impacted. Given that IBM Security Verify Access and Verify Identity Access are identity and access management platforms, exploitation could expose authentication tokens, user credentials, policy configurations, and other sensitive identity data, potentially enabling further lateral movement within an enterprise environment (GitHub Advisory, IBM Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit as of the time of publication (GitHub Advisory). The EPSS score is approximately 0.248% (16th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated session, which limits the attack surface compared to unauthenticated vulnerabilities, though the low complexity and no user interaction requirement make it accessible to any authenticated attacker.
IBM has released patches addressing this vulnerability; organizations should apply the available security updates for IBM Security Verify Access (versions 10.0 through 10.0.9.2) and IBM Verify Identity Access (versions 11.0 through 11.0.3) as detailed in the IBM support advisory (IBM Advisory). As interim measures, restrict network access to IBM Verify Access management interfaces to trusted networks and IP ranges, and implement strong authentication controls to limit the pool of authenticated users. Monitor audit logs for anomalous privilege escalation activity from authenticated accounts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."