Junglewise Threat Intelligence

CVE-2026-13260: IBM Verify Identity Access denial of service in request validation

CVE-2026-13260 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: IBM Verify Identity Access. Vendors: IBM.

Executive brief

IBM Verify Identity Access is an identity and access management platform used to authenticate and authorize users to enterprise applications. Due to insufficient validation of incoming request resources, a remote attacker can trigger a denial of service condition that crashes or hangs the service, making it unavailable to legitimate users.

Technical details

The vulnerability is a result of uncontrolled recursion (CWE-674) in IBM Verify Identity Access that occurs due to insufficient validation of incoming request resources. The flaw is remotely exploitable over the network without requiring authentication or user interaction (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U). An unauthenticated remote attacker can send specially crafted requests that cause the application to enter an infinite or deeply nested recursive loop, exhausting system resources and resulting in a denial of service. IBM has issued a security bulletin addressing this vulnerability.

Affected products

  • IBM Verify Identity Access

Timeline

  • 2026-09-14: disclosed

References

Related threats