ZeroHour

CVE-2026-13260

moderate

Unauthenticated Denial of Service in IBM Verify Identity Access

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-13260 is a resource-exhaustion vulnerability (CWE-770, allocation of resources without limits or throttling) in IBM Verify Identity Access, IBM's enterprise identity and access management platform. A remote, unauthenticated attacker can trigger it by sending crafted network requests that are not properly validated, causing excessive resource consumption and crashing or hanging the service. The impact is availability-only (no confidentiality or integrity impact), but with a CVSS 3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/A:H), an attacker with no credentials or user interaction can repeatedly take down authentication and single-sign-on services for an organization. Organizations running affected IBM Verify Identity Access deployments (formerly IBM Security Verify Access / ISAM) are at risk of users being unable to authenticate while the service is exhausted. It is not listed in the CISA KEV catalog, no public proof-of-concept is known, and no in-the-wild exploitation has been reported.

What to do: Check the IBM PSIRT advisory for CVE-2026-13260 and upgrade affected IBM Verify Identity Access deployments to the fixed releases it specifies. As an interim mitigation, place rate limiting and request-size/connection throttling at a reverse proxy or WAF in front of Verify Access endpoints, and avoid exposing authentication or administrative interfaces directly to the internet. Monitor appliance CPU, memory, thread, and connection usage for abnormal spikes that could indicate resource-exhaustion attempts.

Affected
IBM Verify Identity Access
Estimated exposure
moderate≈1,000–10,000 internet-reachable deployments (estimated) — IBM Verify Identity Access is an enterprise IAM product typically deployed by large organizations rather than consumers, and public internet scans historically show on the order of low thousands of exposed IBM Verify/Security Access…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.