CVE-2026-7364: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in IBM Verify Identity Access
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.
AI Analysis
Technical Summary
IBM Verify Identity Access versions 11.0 through 11.0.2 and IBM Security Verify Access versions 10.0 through 10.0.9.1 contain an open redirect vulnerability (CWE-601). This flaw allows attackers to create specially crafted requests that redirect victims to untrusted external websites. The vulnerability could be leveraged in phishing campaigns to deceive users. The CVSS 3.1 base score is 3.1, reflecting a low severity with network attack vector, high attack complexity, no privileges required, user interaction required, and limited confidentiality impact. No vendor advisory or patch information is currently available, and the vulnerability is not related to cloud services.
Potential Impact
The vulnerability enables attackers to redirect users to arbitrary external websites via crafted URLs, which can facilitate phishing attacks. There is no direct impact on confidentiality, integrity, or availability of the affected products. The overall severity is low due to the requirement for user interaction and high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should be cautious of suspicious URLs that appear to originate from IBM Verify Identity Access or IBM Security Verify Access. No official mitigation or workaround has been provided by IBM at this time.
CVE-2026-7364: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in IBM Verify Identity Access
Description
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.
CVSS v3.1
Score 3.1low
Affected software
cpe:2.3:a:ibm:verify_identity_access:11.0:*:*:*:*:*:*:*cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*cpe:2.3:a:ibm:verify_identity_access:11.0.2:*:*:*:*:*:*:*cpe:2.3:a:ibm:security_verify_access:10.0:*:*:*:*:*:*:*cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*cpe:2.3:a:ibm:security_verify_access:10.0.9.1:*:*:*:*:*:*:*Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
IBM Verify Identity Access versions 11.0 through 11.0.2 and IBM Security Verify Access versions 10.0 through 10.0.9.1 contain an open redirect vulnerability (CWE-601). This flaw allows attackers to create specially crafted requests that redirect victims to untrusted external websites. The vulnerability could be leveraged in phishing campaigns to deceive users. The CVSS 3.1 base score is 3.1, reflecting a low severity with network attack vector, high attack complexity, no privileges required, user interaction required, and limited confidentiality impact. No vendor advisory or patch information is currently available, and the vulnerability is not related to cloud services.
Potential Impact
The vulnerability enables attackers to redirect users to arbitrary external websites via crafted URLs, which can facilitate phishing attacks. There is no direct impact on confidentiality, integrity, or availability of the affected products. The overall severity is low due to the requirement for user interaction and high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should be cautious of suspicious URLs that appear to originate from IBM Verify Identity Access or IBM Security Verify Access. No official mitigation or workaround has been provided by IBM at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- ibm
- Date Reserved
- 2026-04-28T20:43:22.842Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5b5eb02d1edb114c7fb36f
Added to database: 07/18/2026, 11:08:32 UTC
Last enriched: 07/25/2026, 22:53:14 UTC
Last updated: 08/30/2026, 10:52:11 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.