Junglewise Threat Intelligence

CVE-2026-1343: IBM Verify Identity Access SSRF in Reverse Proxy

CVE-2026-1343 · Severity: high · CVSS 7.2 · Published 2026-04-08

Technologies: IBM Security Verify Access Container, IBM Verify Identity Access, IBM Verify Identity Access Container, IBM Security Verify Access. Vendors: IBM.

Executive brief

IBM Verify Identity Access is a security solution used to manage user identities and control access to corporate applications. A vulnerability in its reverse proxy component allows unauthorized individuals to reach internal authentication systems that should be hidden. This could lead to unauthorized access to sensitive internal services or the exposure of configuration data.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the reverse proxy component of IBM Verify Identity Access and Security Verify Access. An unauthenticated remote attacker can exploit this flaw to send requests to internal authentication endpoints that are intended to be isolated from the public network. The vulnerability is characterized by a CVSS score of 7.2, indicating it is easily exploitable over the network without user interaction. Successful exploitation allows the attacker to interact with internal services, potentially leading to information disclosure or unauthorized configuration changes. Affected versions include the 10.0 and 11.0 release cycles for both standard and containerized deployments.

Affected products

  • IBM Verify Identity Access Container 11.0 through 11.0.2
  • IBM Security Verify Access Container 10.0 through 10.0.9.1
  • IBM Verify Identity Access 11.0 through 11.0.2
  • IBM Security Verify Access 10.0 through 10.0.9.1

Timeline

  • 2026-04-08: disclosed: Initial publication of the vulnerability advisory

References

Related threats