Skip to content
IBMCVE-2026-7364

IBM Security Verify Access: open redirect

Low3.1CVE-2026-7364 · Published Jul 17, 2026 · updated Jul 30, 2026

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially crafted request to redirect a victim to arbitrary Web sites.

IBM advisory

Affected versions

PackageAffectedFixed in
Security Verify Access
Product
>= 10.0, <= 10.0.9.1No fix yet
Security Verify Access Container
Product
>= 10.0, <= 10.0.9.1No fix yet
Verify Identity Access
Product
>= 11.0, <= 11.0.2No fix yet
Verify Identity Access Container
Product
>= 11.0, <= 11.0.2No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-601

More IBM advisories

All IBM
Advisory
IBM Langflow OSS: insecure direct object reference
High8.1Jul 17
IBM Langflow OSS: hard-coded credentials
Critical9.8Jul 17
IBM Langflow OSS: remote code execution
Critical9.8Jul 17
IBM Langflow OSS: privilege escalation
Critical9.9Jul 17
IBM Langflow OSS: improper input validation
Critical9.9Jul 17
IBM Security Verify Access: information disclosure
Medium5.3Jul 17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.