IBMCVE-2026-13267
IBM Security Verify Access: authenticated user could gain privileges of another...
High8.1CVE-2026-13267 · Published Aug 12, 2026 · updated Aug 17, 2026
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Security Verify Access Product | >= 10.0, <= 10.0.9.2 | No fix yet |
| Security Verify Access Container Product | >= 10.0, <= 10.0.9.2 | No fix yet |
| Verify Identity Access Product | >= 11.0, <= 11.0.3 | No fix yet |
| Verify Identity Access Container Product | >= 11.0, <= 11.0.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-302
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | IBM DataPower Gateway: race condition | Medium4.2 | No fix yet |
| Aug 12 | IBM Db2: buffer overflow | High8.4 | No fix yet |
| Aug 12 | IBM i: denial of service | High8.2 | No fix yet |
| Aug 12 | IBM DOORS Next: improper authentication | Critical10.0 | No fix yet |
| Aug 12 | IBM Db2: improper authorization | Medium4.3 | No fix yet |
| Aug 12 | IBM i Access Client Solutions: code execution | High7.8 | No fix yet |