CVE-2026-13297
—Unauthenticated Info Disclosure in IBM Verify Identity Access Advanced Access Control
IBM Verify Identity Access (Advanced Access Control component) is affected by an information disclosure vulnerability, assigned CWE-1336 (improper neutralization of special elements used in a template engine), though IBM has not yet published detailed technical specifics. Based on the CVSS 3.1 vector, the flaw can be triggered remotely over the network by an unauthenticated attacker, with low attack complexity and no user interaction required. Successful exploitation yields a high-impact confidentiality loss — disclosure of sensitive information — with no impact on integrity or availability. Organizations running IBM Verify Identity Access with the Advanced Access Control component are affected; specific affected version ranges have not been disclosed in the available data. Exploitation is not currently observed: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Monitor IBM's PSIRT advisory for CVE-2026-13297 for the published affected and fixed version ranges and apply the vendor patch promptly once released. Until patched, restrict network access to Verify Identity Access / Advanced Access Control interfaces to trusted networks and review logs for anomalous information-access activity. Because the flaw requires no credentials or user interaction, prioritize hardening any internet-facing Verify Identity Access deployments first.
| IBM Verify Identity Access - Advanced Access Control component | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
- Weakness
- CWE-1336
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.