CVE-2026-2475
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation

Overview

CVE-2026-2475 is an open redirect vulnerability (CWE-601) affecting multiple IBM identity and access management products. It allows remote attackers to conduct phishing attacks by redirecting victims to arbitrary websites via specially crafted requests. Affected products include IBM Verify Identity Access Container 11.0–11.0.2, IBM Security Verify Access Container 10.0–10.0.9.1, IBM Verify Identity Access 11.0–11.0.2, and IBM Security Verify Access 10.0–10.0.9.1. The vulnerability was published on April 1, 2026, with patches available from IBM. The CVSS v3.1 base score is 4.7 (Medium) per Feedly/NVD, while the GitHub Advisory Database and ENISA rate it at 3.1 (Low) (GitHub Advisory, IBM Advisory).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), where the application accepts user-controlled input specifying an external link and uses it in a redirect without adequate validation. An unauthenticated remote attacker can craft a specially formed HTTP request targeting the vulnerable redirect parameter, causing the application to forward the victim's browser to an attacker-controlled website. Exploitation requires user interaction — specifically, a victim must click a malicious link that leverages the trusted IBM domain as the originating host, increasing the credibility of the redirect. No public proof-of-concept code has been identified (GitHub Advisory, IBM Advisory).

Impact

The primary impact is facilitation of phishing attacks: victims clicking a crafted link originating from a trusted IBM domain are silently redirected to attacker-controlled websites, where they may be subjected to credential harvesting, malware delivery, or other social engineering attacks. There is no direct confidentiality or availability impact on the IBM product itself; the integrity impact is limited to the deception of end users. The use of a trusted IBM domain as the redirect origin significantly increases the likelihood that victims will trust and follow the malicious link (GitHub Advisory, IBM Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible IBM Verify Identity Access or IBM Security Verify Access instances running affected versions (11.0–11.0.2 or 10.0–10.0.9.1) using internet scanning tools or targeted searches.
  2. Identify redirect parameter: Locate the vulnerable URL redirect parameter within the IBM application's authentication or navigation flow (e.g., a redirect, target, or goto parameter in login or session management endpoints).
  3. Craft malicious URL: Construct a URL using the legitimate IBM domain with the redirect parameter pointing to an attacker-controlled site (e.g., https://ibm-instance.example.com/login?redirect=https://attacker.com/phishing).
  4. Deliver to victim: Send the crafted URL to targeted users via email, messaging platforms, or other social engineering channels, leveraging the trusted IBM domain to increase credibility.
  5. Harvest credentials or deliver malware: When the victim clicks the link and is redirected to the attacker's site, present a convincing phishing page to steal credentials or initiate malware download (GitHub Advisory, IBM Advisory).

Indicators of compromise

  • Network: HTTP requests to IBM Verify Identity Access or Security Verify Access endpoints containing redirect/target parameters with external or unexpected URLs; outbound redirects (HTTP 3xx responses) from the IBM application to non-IBM domains.
  • Logs: Web server or application access logs showing requests with redirect parameters pointing to external domains (e.g., redirect=https://, target=http://, goto=https:// followed by non-corporate URLs); unusual referrer patterns in downstream phishing site logs tracing back to the IBM application.
  • User Reports: End users reporting unexpected redirects after clicking IBM-branded links, or phishing pages that appear after authenticating to IBM services.

Mitigation and workarounds

IBM has released patches for all affected product lines; organizations should update to versions beyond 11.0.2 (for IBM Verify Identity Access and its Container variant) and beyond 10.0.9.1 (for IBM Security Verify Access and its Container variant) as detailed in the IBM security bulletin (IBM Advisory). As a complementary measure, implement URL validation controls at the application or WAF layer to block or alert on redirect parameters containing external domains. User security awareness training should be conducted to help users recognize suspicious links, even those originating from trusted domains. Organizations should also consider implementing Content Security Policy (CSP) headers and monitoring web application logs for anomalous redirect activity.

Community reactions

Security news outlets including GBHackers and CyberPress covered the vulnerability as part of broader reporting on IBM Security Verify Access flaws, noting the phishing risk posed by the open redirect (GBHackers, CyberPress). No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage. IBM published an official security bulletin acknowledging the issue and providing remediation guidance (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM Security Verify Access (formerly ISAM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-1346HIGH7.8
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 08, 2026
CVE-2026-4938MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-5926MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 23, 2026
CVE-2026-8861MEDIUM5.3
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-7364LOW3.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management