ZeroHour

CVE-2026-13297

Unauthenticated Info Disclosure in IBM Verify Identity Access Advanced Access Control

CVSS 3.1
7.5 high
EPSS
<1%p16
Published
()
Modified
AI analysis

IBM Verify Identity Access (Advanced Access Control component) is affected by an information disclosure vulnerability, assigned CWE-1336 (improper neutralization of special elements used in a template engine), though IBM has not yet published detailed technical specifics. Based on the CVSS 3.1 vector, the flaw can be triggered remotely over the network by an unauthenticated attacker, with low attack complexity and no user interaction required. Successful exploitation yields a high-impact confidentiality loss — disclosure of sensitive information — with no impact on integrity or availability. Organizations running IBM Verify Identity Access with the Advanced Access Control component are affected; specific affected version ranges have not been disclosed in the available data. Exploitation is not currently observed: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Monitor IBM's PSIRT advisory for CVE-2026-13297 for the published affected and fixed version ranges and apply the vendor patch promptly once released. Until patched, restrict network access to Verify Identity Access / Advanced Access Control interfaces to trusted networks and review logs for anomalous information-access activity. Because the flaw requires no credentials or user interaction, prioritize hardening any internet-facing Verify Identity Access deployments first.

Affected
IBM Verify Identity Access - Advanced Access Control component
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

Weakness
CWE-1336
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.