Remote Information Disclosure in IBM Verify Identity Access and Security Verify Access Products
CVE-2026-1491
5.3MEDIUM
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 1 April 2026
What is CVE-2026-1491?
A security issue exists within IBM Verify Identity Access and IBM Security Verify Access products that could lead to a remote attacker gaining unauthorized access to sensitive information. The vulnerability arises from an inconsistent interpretation of HTTP requests by a reverse proxy, potentially exposing critical data to attackers. Users are encouraged to apply the recommended patches to mitigate risks associated with this vulnerability.
Affected Version(s)
Security Verify Access 10.0 <= 10.0.9.1
Security Verify Access Container 10.0 <= 10.0.9.1
Verify Identity Access 11.0 <= 11.0.2