Junglewise Threat Intelligence

CVE-2026-13272: IBM Verify Identity Access missing origin validation

CVE-2026-13272 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Technologies: IBM Verify Identity Access. Vendors: IBM.

Executive brief

IBM Verify Identity Access lacks proper validation of request origins, allowing remote attackers to perform unauthorized operations on behalf of legitimate users without their knowledge. An attacker can exploit this to impersonate users, access sensitive identity and access data, and potentially escalate attacks against connected systems and networks.

Technical details

The vulnerability is a missing origin validation flaw in IBM Verify Identity Access, a class of weakness that enables Cross-Site Request Forgery (CSRF) or similar attacks. The root cause is insufficient validation of the HTTP Origin or Referer headers when processing requests. An attacker can send a specially crafted request from an attacker-controlled domain to perform actions in the victim's authenticated session, without requiring network access to the victim's network (network attack vector). This allows the attacker to execute privileged operations as the victim, such as modifying access policies or account settings. Patches or workarounds should be available from IBM; consult the IBM support advisory for specific remediation steps.

Affected products

  • IBM Verify Identity Access

Timeline

  • 2026-09-14: disclosed
  • other: CVE-2026-13272 assigned

References

Related threats