CVE-2026-13272
IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.15%
- CWE
- CWE-1385
- Published
- 2026-09-14
- Last modified
- 2026-09-16
Affected products
- IBM Verify Identity Access
- IBM Security Verify Access
- IBM Verify Identity Access Container
- IBM Security Verify Access Container
Weakness type
Related vulnerabilities
- CVE-2025-24964 — Remote Code Execution when accessing a malicious website while Vitest API server is listening
- CVE-2024-48849 — Authentication and Authorization Issues
- CVE-2025-52882 — Claude Code IDE extensions allow websocket connections from arbitrary origins
- CVE-2023-30856 — eDEX-UI cross-site websocket hijacking vulnerability enables remote command execution
- CVE-2023-0957 — An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site WebSocket Hijacking (CSW
- CVE-2023-26114 — Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.
- CVE-2023-2848 — Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a miss
- CVE-2026-44211 — Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability