CVE-2026-13260
moderateUnauthenticated Denial of Service in IBM Verify Identity Access
CVE-2026-13260 is a resource-exhaustion vulnerability (CWE-770, allocation of resources without limits or throttling) in IBM Verify Identity Access, IBM's enterprise identity and access management platform. A remote, unauthenticated attacker can trigger it by sending crafted network requests that are not properly validated, causing excessive resource consumption and crashing or hanging the service. The impact is availability-only (no confidentiality or integrity impact), but with a CVSS 3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/A:H), an attacker with no credentials or user interaction can repeatedly take down authentication and single-sign-on services for an organization. Organizations running affected IBM Verify Identity Access deployments (formerly IBM Security Verify Access / ISAM) are at risk of users being unable to authenticate while the service is exhausted. It is not listed in the CISA KEV catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.
What to do: Check the IBM PSIRT advisory for CVE-2026-13260 and upgrade affected IBM Verify Identity Access deployments to the fixed releases it specifies. As an interim mitigation, place rate limiting and request-size/connection throttling at a reverse proxy or WAF in front of Verify Access endpoints, and avoid exposing authentication or administrative interfaces directly to the internet. Monitor appliance CPU, memory, thread, and connection usage for abnormal spikes that could indicate resource-exhaustion attempts.
| IBM Verify Identity Access | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.