
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1491 is an HTTP Request Smuggling vulnerability affecting multiple IBM identity and access management products. It allows a remote, unauthenticated attacker to access sensitive information by exploiting inconsistent interpretation of HTTP requests by a reverse proxy component. Affected products include IBM Verify Identity Access Container (versions 11.0–11.0.2), IBM Security Verify Access Container (versions 10.0–10.0.9.1), IBM Verify Identity Access (versions 11.0–11.0.2), and IBM Security Verify Access (versions 10.0–10.0.9.1). The vulnerability was published on April 1, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, IBM Advisory).
The root cause is classified as CWE-444 (Inconsistent Interpretation of HTTP Requests / HTTP Request Smuggling), mapped to CAPEC-33. The vulnerability arises because the reverse proxy component in IBM's Verify/Security Verify Access products parses HTTP requests differently than the backend server, allowing an attacker to craft ambiguous HTTP requests that are interpreted inconsistently between the proxy and the origin server. This discrepancy can be exploited over the network without authentication or user interaction, making it accessible to any remote attacker who can reach the affected service (Github Advisory, IBM Advisory).
Successful exploitation allows a remote, unauthenticated attacker to access sensitive information from affected IBM identity and access management systems. The impact is limited to confidentiality — there is no integrity or availability impact — but given the identity-management nature of the affected products, exposed data could include authentication tokens, session data, or user credentials. The attack requires no privileges or user interaction, increasing the risk of opportunistic exploitation against internet-facing deployments (Github Advisory, IBM Advisory).
Content-Length and Transfer-Encoding headers (CL.TE or TE.CL smuggling techniques).Content-Length and Transfer-Encoding headers present simultaneously targeting IBM Verify/Security Verify Access endpoints; unexpected HTTP responses containing data not matching the original request.IBM has released patches addressing this vulnerability; users should upgrade IBM Verify Identity Access and IBM Verify Identity Access Container to versions beyond 11.0.2, and IBM Security Verify Access and IBM Security Verify Access Container to versions beyond 10.0.9.1 (IBM Advisory). As a configuration-based workaround, administrators should review and align reverse proxy HTTP parsing settings with backend server behavior to eliminate ambiguous request interpretation. Additionally, monitoring for anomalous HTTP traffic patterns (e.g., requests with conflicting Content-Length and Transfer-Encoding headers) can help detect exploitation attempts.
Several cybersecurity news outlets covered this vulnerability following its April 2026 disclosure, including GBHackers, CyberSecurityNews, CyberPress, and Cybernoz, generally framing it as part of a broader set of IBM Verify Access vulnerabilities allowing remote attackers to access sensitive data. Coverage noted the lack of active exploitation and the availability of patches. No notable independent researcher commentary or vendor statements beyond the IBM security bulletin have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."