IBMCVE-2026-13276
IBM Security Verify Access: cross-site scripting
Medium6.1CVE-2026-13276 · Published Sep 14, 2026 · updated Sep 16, 2026
IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access Container 10.0.0 through 10.0.9.2 Interim Fix 001.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Security Verify Access Product | >= 10.0.0, <= 10.0.9.2 Interim Fix 001 | No fix yet |
| Security Verify Access Container Product | >= 10.0.0, <= 10.0.9.2 Interim Fix 001 | No fix yet |
| Verify Identity Access Product | >= 11.0.0, <= 11.0.3 Interim Fix 001 | No fix yet |
| Verify Identity Access Container Product | >= 11.0.0, <= 11.0.3 Interim Fix 001 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-79
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | IBM MQ: information disclosure | Medium6.8 | No fix yet |
| Sep 14 | IBM Business Automation Workflow containers and traditional: XML external entity | High7.1 | No fix yet |
| Sep 14 | IBM Cloud Pak for Business Automation: missing authorization | Medium5.4 | No fix yet |
| Sep 14 | IBM Cloud Pak for Business Automation: denial of service | Medium6.5 | No fix yet |
| Sep 14 | IBM Langflow OSS: server-side request forgery | Critical9.6 | No fix yet |
| Sep 14 | IBM Sterling Secure Proxy: improper authorization | Medium4.3 | No fix yet |