
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1343 is a Server-Side Request Forgery (SSRF) vulnerability affecting multiple IBM identity and access management products. It allows unauthenticated remote attackers to bypass Reverse Proxy protections and directly contact internal authentication endpoints. Affected products include IBM Verify Identity Access Container 11.0–11.0.2, IBM Security Verify Access Container 10.0–10.0.9.1, IBM Verify Identity Access 11.0–11.0.2, and IBM Security Verify Access 10.0–10.0.9.1. The vulnerability was published on April 8, 2026, with a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, IBM Advisory).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the affected IBM products fail to sufficiently validate or restrict outbound requests, allowing an attacker to reach internal authentication endpoints that are intended to be shielded by the Reverse Proxy component. Exploitation requires no authentication, no user interaction, and only network access, making it trivially accessible to any remote attacker. The changed scope (S:C) in the CVSS vector indicates that a successful attack can impact resources beyond the vulnerable component itself — specifically, internal authentication infrastructure. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, IBM Advisory).
Successful exploitation allows an unauthenticated attacker to bypass the Reverse Proxy and interact directly with internal authentication endpoints, potentially exposing sensitive authentication system data and enabling unauthorized modification of authentication configurations. The confidentiality and integrity impacts are rated Low, but the changed scope means the attack can affect components beyond the directly vulnerable service. This could facilitate credential harvesting, authentication bypass, or serve as a pivot point for deeper access into protected internal systems (GitHub Advisory, IBM Advisory).
http://127.0.0.1:<port>/internal-auth-endpoint) that are normally protected by the Reverse Proxy, embedding this in the vulnerable parameter.IBM has released patches for all affected product lines; organizations should update IBM Verify Identity Access and IBM Verify Identity Access Container to versions beyond 11.0.2, and IBM Security Verify Access and IBM Security Verify Access Container to versions beyond 10.0.9.1. As an interim workaround, implement network segmentation to restrict access to internal authentication endpoints so they are not reachable even via SSRF. Additionally, monitor for suspicious requests attempting to contact internal endpoints through the Reverse Proxy (IBM Advisory, IBM Support).
The vulnerability received coverage from several cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, which highlighted the risk of remote attackers accessing sensitive authentication data (GBHackers, CyberSecurityNews). CISA included the CVE in its weekly vulnerability summary bulletin for the week of April 6, 2026 (CISA Bulletin). Social media activity was limited to automated CVE tracking accounts on Mastodon and Bluesky, with no notable researcher commentary or significant community debate observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."