Junglewise Threat Intelligence

CVE-2026-13276: IBM Verify Identity Access parameter injection in reverse proxy

CVE-2026-13276 · Severity: medium · CVSS 6.1 · Published 2026-09-14

Technologies: IBM Verify Identity Access, IBM Verify Identity Access Container. Vendors: IBM.

Executive brief

IBM Verify Identity Access is an identity and access management solution used to control user authentication and authorization in enterprise environments. A vulnerability allows attackers to inject parameters into requests forwarded to third-party services, potentially enabling unauthorized access, data interception, or manipulation of downstream systems that trust the reverse proxy.

Technical details

The vulnerability (CVE-2026-11927) is a parameter injection flaw in IBM Verify Identity Access reverse proxy functionality, classified as improper neutralization of special elements in output (CWE-74). The reverse proxy fails to properly validate and sanitize parameters before forwarding requests to third-party services, allowing an attacker with network access to inject malicious parameters. This could enable attackers to bypass authentication, manipulate business logic, or access unauthorized data on downstream systems. The vulnerability affects versions 10.0.0 through 10.0.9.2 Interim Fix 001 and 11.0.0 through 11.0.3 Interim Fix 001; patches are available from IBM.

Affected products

  • IBM Verify Identity Access 10.0.0 through 10.0.9.2 Interim Fix 001, 11.0.0 through 11.0.3 Interim Fix 001
  • IBM Verify Identity Access Container 10.0.0 through 10.0.9.2 Interim Fix 001, 11.0.0 through 11.0.3 Interim Fix 001

Timeline

  • 2026-09-14: disclosed

References

Related threats