CVE-2026-13272

IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.

  • Published Sep 14, 2026
  • CVSS 5.4 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-13272 at the National Vulnerability Database