Description
IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Published: 2026-09-14
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Phishing and potential information disclosure via an open redirect
Action: Update
AI Analysis

Impact

IBM Verify Identity users to a crafted URL appearing to be from a legitimate site. By persuading a victim to visit this URL, the attacker can spoof the displayed site and redirect the victim to a malicious web location that looks trusted, enabling phishing attacks or the theft of highly sensitive information. The flaw is specifically a CWE‑601 type vulnerability involving improper handling of redirect URLs.

Affected Systems

The affected products are IBM Verify Identity Access and IBM Security Verify Access, including the Container variants. The patches that address this vulnerability are IBM Verify Identity Access v11.0.3 IF2 and IBM Security Verify Access v10.0.9.2 IF2. Container images should be updated following IBM’s container documentation link.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the public web interfaces of the affected products, where an attacker can supply a malicious redirect target. Because the flaw enables phishing that could lead to credential compromise or further attacks, the risk remains significant for environments that expose these services to untrusted users.

Generated by OpenCVE AI on September 20, 2026 at 22:02 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly. Appliance Affected Products Fix availability IBM Verify Identity Access Download IBM Verify Identity Access v11.0.3 IF2 https://www.ibm.com/support/fixcentral/quickorder IBM Security Verify Access Download IBM Security Verify Access v10.0.9.2 IF2 https://www.ibm.com/support/fixcentral/quickorder Container Container Download https://docs.verify.ibm.com/ibm-security-verify-access/docs/containers


OpenCVE Recommended Actions

  • Apply the IBM Verify Identity Access v11.0.3 IF2 patch and the IBM Security Verify Access v10.0.9.2 IF2 patch as provided by IBM.
  • For container deployments, upgrade to the latest container image using IBM’s container download and documentation link.
  • Configure redirect targets to allow only trusted domains by implementing a whitelist or strict validation of the redirect URL to eliminate the open redirect flaw.

Generated by OpenCVE AI on September 20, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Title Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
First Time appeared Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
Weaknesses CWE-601
CPEs cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*
Vendors & Products Ibm
Ibm security Verify Access
Ibm security Verify Access Container
Ibm verify Identity Access
Ibm verify Identity Access Container
References

Subscriptions

Ibm Security Verify Access Security Verify Access Container Verify Identity Access Verify Identity Access Container
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T17:23:12.149Z

Reserved: 2026-06-24T21:43:49.783Z

Link: CVE-2026-13277

cve-icon Vulnrichment

Updated: 2026-09-15T17:23:09.011Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T21:17:01.680

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-13277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:15:05Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')