Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
Published Jul 17, 2026
6.1
MEDIUMCVSS 3.1
EPSS 0.36%
Description
IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.
Affected products
-
Affected
- ≥ 10.0, ≤ 10.0.9.1
-
Affected
- ≥ 10.0, ≤ 10.0.9.1
-
Affected
- ≥ 11.0, ≤ 11.0.2
-
Affected
- ≥ 11.0, ≤ 11.0.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| IBM | Security Verify Access | unknown | Affected
|
| IBM | Security Verify Access Container | unknown | Affected
|
| IBM | Verify Identity Access | unknown | Affected
|
| IBM | Verify Identity Access Container | unknown | Affected
|
- ≥ 10.0.0 · ≤ 10.0.9.1
- ≥ 10.0.0.0 · ≤ 10.0.9.1
- ≥ 11.0 · ≤ 11.0.2.0
- ≥ 11.0.0.0 · ≤ 11.0.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
IBM encourages customers to update their systems promptly.Appliance:Affected Products and VersionsFix availabilityIBM Verify Identity Access 11.0 - 11.0.2Download IBM Verify Identity Access v11.0.3IBM Security Verify Access 10.0 0 - 10.0.9.1Download IBM Security Verify Access v10.0.9.2Container:Container Download
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45291 Advisory
- https://www.ibm.com/support/pages/node/7279510 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45291 | Advisory | |
| https://www.ibm.com/support/pages/node/7279510 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data