Phishing Risk in IBM Verify Identity Access
CVE-2026-13277

4.7MEDIUM

What is CVE-2026-13277?

IBM Verify Identity Access is vulnerable to an attack where a remote adversary can exploit open redirects to craft a phishing scheme. By tricking a user into visiting a manipulated URL, an attacker can conceal the actual destination of the link, redirecting users to a malicious site. This deceptive behavior may lead to unauthorized access to sensitive user information or enable further malicious activities.

Affected Version(s)

Security Verify Access 10.0.0 <= 10.0.9.2 Interim Fix 001

Security Verify Access Container 10.0.0 <= 10.0.9.2 Interim Fix 001

Verify Identity Access 11.0.0 <= 11.0.3 Interim Fix 001

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.