CVE-2026-13277
Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th
IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
| CWE | CWE-601 |
| Vendor | ibm |
| Product | verify identity access |
| Published | Sep 14, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for ibm verify identity access
Be the first to know when new medium vulnerabilities affecting ibm verify identity access are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
IBM / Verify Identity Access
11.0.0 ≤ 11.0.3 Interim Fix 001
IBM / Security Verify Access
10.0.0 ≤ 10.0.9.2 Interim Fix 001
IBM / Verify Identity Access Container
11.0.0 ≤ 11.0.3 Interim Fix 001
IBM / Security Verify Access Container
10.0.0 ≤ 10.0.9.2 Interim Fix 001