Junglewise Threat Intelligence

CVE-2026-7364: IBM Verify Identity Access open redirect vulnerability

CVE-2026-7364 · Severity: low · CVSS 3.1 · Published 2026-07-17

Executive brief

IBM Verify Identity Access is a solution used by organizations to manage user identities and control access to applications. A security flaw in this product could allow an attacker to trick users into visiting malicious websites by clicking on a link that appears to belong to a trusted corporate portal. This technique is commonly used in phishing campaigns to steal user credentials or deliver malware.

Technical details

An open redirect vulnerability (CWE-601) exists in IBM Verify Identity Access and IBM Security Verify Access (including containerized versions). The flaw is caused by improper validation of user-supplied input used in redirection targets. A remote, unauthenticated attacker can exploit this by crafting a URL that, when clicked by a victim, redirects them from the trusted IBM Verify domain to an arbitrary external malicious website. While the attack requires user interaction and has a high complexity (AC:H), it can be used to increase the perceived legitimacy of phishing attempts. Affected versions include 10.0.x up to 10.0.9.1 and 11.0.x up to 11.0.2.

Affected products

  • IBM Verify Identity Access 11.0 through 11.0.2
  • IBM Security Verify Access 10.0 through 10.0.9.1
  • IBM Verify Identity Access Container 11.0 through 11.0.2
  • IBM Security Verify Access Container 10.0 through 10.0.9.1

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References

Related threats