CVE-2026-1491
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation

Overview

CVE-2026-1491 is an HTTP Request Smuggling vulnerability affecting multiple IBM identity and access management products. It allows a remote, unauthenticated attacker to access sensitive information by exploiting inconsistent interpretation of HTTP requests by a reverse proxy component. Affected products include IBM Verify Identity Access Container (versions 11.0–11.0.2), IBM Security Verify Access Container (versions 10.0–10.0.9.1), IBM Verify Identity Access (versions 11.0–11.0.2), and IBM Security Verify Access (versions 10.0–10.0.9.1). The vulnerability was published on April 1, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, IBM Advisory).

Technical details

The root cause is classified as CWE-444 (Inconsistent Interpretation of HTTP Requests / HTTP Request Smuggling), mapped to CAPEC-33. The vulnerability arises because the reverse proxy component in IBM's Verify/Security Verify Access products parses HTTP requests differently than the backend server, allowing an attacker to craft ambiguous HTTP requests that are interpreted inconsistently between the proxy and the origin server. This discrepancy can be exploited over the network without authentication or user interaction, making it accessible to any remote attacker who can reach the affected service (Github Advisory, IBM Advisory).

Impact

Successful exploitation allows a remote, unauthenticated attacker to access sensitive information from affected IBM identity and access management systems. The impact is limited to confidentiality — there is no integrity or availability impact — but given the identity-management nature of the affected products, exposed data could include authentication tokens, session data, or user credentials. The attack requires no privileges or user interaction, increasing the risk of opportunistic exploitation against internet-facing deployments (Github Advisory, IBM Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing IBM Security Verify Access or IBM Verify Identity Access deployments running affected versions (10.0–10.0.9.1 or 11.0–11.0.2) using network scanning tools such as Shodan or Censys, targeting known IBM product banners or default ports.
  2. Craft ambiguous HTTP request: Construct an HTTP request that exploits the parsing discrepancy between the reverse proxy and the backend server — for example, using conflicting Content-Length and Transfer-Encoding headers (CL.TE or TE.CL smuggling techniques).
  3. Send smuggled request: Transmit the crafted request to the target's reverse proxy endpoint without authentication. The proxy forwards a differently-interpreted version of the request to the backend server.
  4. Access sensitive information: The backend server processes the smuggled portion of the request, potentially exposing sensitive data (e.g., session tokens, internal responses, or user data) in the HTTP response returned to the attacker (Github Advisory, IBM Advisory).

Indicators of compromise

  • Network: Unusual HTTP requests with both Content-Length and Transfer-Encoding headers present simultaneously targeting IBM Verify/Security Verify Access endpoints; unexpected HTTP responses containing data not matching the original request.
  • Logs: Reverse proxy access logs showing malformed or ambiguous HTTP requests with conflicting length headers; backend server logs showing requests that do not correspond to any client-initiated session.
  • Process/Application: Unexpected data appearing in HTTP responses to legitimate users (a hallmark of request smuggling); error messages in proxy or application logs related to HTTP parsing inconsistencies.

Mitigation and workarounds

IBM has released patches addressing this vulnerability; users should upgrade IBM Verify Identity Access and IBM Verify Identity Access Container to versions beyond 11.0.2, and IBM Security Verify Access and IBM Security Verify Access Container to versions beyond 10.0.9.1 (IBM Advisory). As a configuration-based workaround, administrators should review and align reverse proxy HTTP parsing settings with backend server behavior to eliminate ambiguous request interpretation. Additionally, monitoring for anomalous HTTP traffic patterns (e.g., requests with conflicting Content-Length and Transfer-Encoding headers) can help detect exploitation attempts.

Community reactions

Several cybersecurity news outlets covered this vulnerability following its April 2026 disclosure, including GBHackers, CyberSecurityNews, CyberPress, and Cybernoz, generally framing it as part of a broader set of IBM Verify Access vulnerabilities allowing remote attackers to access sensitive data. Coverage noted the lack of active exploitation and the availability of patches. No notable independent researcher commentary or vendor statements beyond the IBM security bulletin have been identified.

Additional resources


SourceThis report was generated using AI

Related IBM Security Verify Access (formerly ISAM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-1346HIGH7.8
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 08, 2026
CVE-2026-4938MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-5926MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 23, 2026
CVE-2026-8861MEDIUM5.3
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-7364LOW3.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management