CVE-2026-13297 PUBLISHED

Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access

Assigner: ibm
Reserved: 24.06.2026 Published: 04.09.2026 Updated: 04.09.2026

IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

Product Status

Vendor IBM
Product Verify Identity Access
Versions
  • affected from 11.0.0 to 11.0.3 Interim Fix 001 (incl.)
Vendor IBM
Product Security Verify Access
Versions
  • affected from 10.0.0 to 10.0.9.2 Interim Fix 001 (incl.)
Vendor IBM
Product Verify Identity Access Container
Versions
  • affected from 11.0.0 to 11.0.3 Interim Fix 001 (incl.)
Vendor IBM
Product Security Verify Access Container
Versions
  • affected from 10.0.0 to 10.0.9.2 Interim Fix 001 (incl.)

Solutions

IBM encourages customers to update their systems promptly.

Appliance

Affected Products

Fix availability

IBM Verify Identity Access

Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder

IBM Security Verify Access

Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder

Container

Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers

References

Problem Types

  • CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine CWE