
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2475 is an open redirect vulnerability (CWE-601) affecting multiple IBM identity and access management products. It allows remote attackers to conduct phishing attacks by redirecting victims to arbitrary websites via specially crafted requests. Affected products include IBM Verify Identity Access Container 11.0–11.0.2, IBM Security Verify Access Container 10.0–10.0.9.1, IBM Verify Identity Access 11.0–11.0.2, and IBM Security Verify Access 10.0–10.0.9.1. The vulnerability was published on April 1, 2026, with patches available from IBM. The CVSS v3.1 base score is 4.7 (Medium) per Feedly/NVD, while the GitHub Advisory Database and ENISA rate it at 3.1 (Low) (GitHub Advisory, IBM Advisory).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), where the application accepts user-controlled input specifying an external link and uses it in a redirect without adequate validation. An unauthenticated remote attacker can craft a specially formed HTTP request targeting the vulnerable redirect parameter, causing the application to forward the victim's browser to an attacker-controlled website. Exploitation requires user interaction — specifically, a victim must click a malicious link that leverages the trusted IBM domain as the originating host, increasing the credibility of the redirect. No public proof-of-concept code has been identified (GitHub Advisory, IBM Advisory).
The primary impact is facilitation of phishing attacks: victims clicking a crafted link originating from a trusted IBM domain are silently redirected to attacker-controlled websites, where they may be subjected to credential harvesting, malware delivery, or other social engineering attacks. There is no direct confidentiality or availability impact on the IBM product itself; the integrity impact is limited to the deception of end users. The use of a trusted IBM domain as the redirect origin significantly increases the likelihood that victims will trust and follow the malicious link (GitHub Advisory, IBM Advisory).
redirect, target, or goto parameter in login or session management endpoints).https://ibm-instance.example.com/login?redirect=https://attacker.com/phishing).redirect=https://, target=http://, goto=https:// followed by non-corporate URLs); unusual referrer patterns in downstream phishing site logs tracing back to the IBM application.IBM has released patches for all affected product lines; organizations should update to versions beyond 11.0.2 (for IBM Verify Identity Access and its Container variant) and beyond 10.0.9.1 (for IBM Security Verify Access and its Container variant) as detailed in the IBM security bulletin (IBM Advisory). As a complementary measure, implement URL validation controls at the application or WAF layer to block or alert on redirect parameters containing external domains. User security awareness training should be conducted to help users recognize suspicious links, even those originating from trusted domains. Organizations should also consider implementing Content Security Policy (CSP) headers and monitoring web application logs for anomalous redirect activity.
Security news outlets including GBHackers and CyberPress covered the vulnerability as part of broader reporting on IBM Security Verify Access flaws, noting the phishing risk posed by the open redirect (GBHackers, CyberPress). No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage. IBM published an official security bulletin acknowledging the issue and providing remediation guidance (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."