CVE-2026-7364
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation

Overview

CVE-2026-7364 is an open redirect vulnerability affecting IBM Verify Identity Access and IBM Security Verify Access products, including their container variants. A remote attacker can exploit this flaw to redirect victims to arbitrary websites, facilitating phishing attacks. Affected versions include IBM Verify Identity Access 11.0 through 11.0.2, IBM Security Verify Access 10.0 through 10.0.9.1, and their respective container editions. The vulnerability was published on July 17, 2026, with a patch made available by IBM on July 8, 2026. It carries a CVSS v3.1 base score of 3.1 (Low) (IBM Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), where the application accepts user-controlled input specifying an external link and uses it in a redirect without adequate validation. An unauthenticated remote attacker can craft a specially crafted HTTP request that causes the application to redirect a victim's browser to an arbitrary, attacker-controlled website. Exploitation requires user interaction (the victim must follow the malicious link) and has high attack complexity, limiting its practical reach. No public proof-of-concept code or detailed technical write-ups have been identified at this time (IBM Advisory, GitHub Advisory).

Impact

Successful exploitation primarily enables phishing attacks by redirecting authenticated or unauthenticated users from a trusted IBM identity management portal to an attacker-controlled site, potentially harvesting credentials or delivering malware. The confidentiality impact is rated Low, with no direct integrity or availability impact. Because the affected products are identity and access management platforms, credential theft via phishing could have downstream consequences including unauthorized access to protected resources (IBM Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible IBM Verify Identity Access or IBM Security Verify Access login portals running affected versions (11.0–11.0.2 or 10.0–10.0.9.1), including container deployments.
  2. Identify redirect parameter: Locate URL parameters in the application that accept redirect targets (e.g., redirect, next, url, or similar query parameters used in authentication flows).
  3. Craft malicious URL: Construct a URL pointing to the legitimate IBM Verify Identity Access portal but with the redirect parameter set to an attacker-controlled site (e.g., https://victim-ibm-portal.example.com/login?redirect=https://attacker.example.com).
  4. Deliver phishing link: Send the crafted URL to targeted users via email, messaging platforms, or other social engineering channels, leveraging the trusted domain of the IBM portal to increase credibility.
  5. Harvest credentials or deliver payload: When the victim clicks the link and interacts with the portal, they are redirected to the attacker's site, which may mimic the IBM login page to steal credentials or serve malicious content (IBM Advisory, GitHub Advisory).

Indicators of compromise

  • Network: HTTP requests to IBM Verify Identity Access or Security Verify Access endpoints containing redirect parameters pointing to external or suspicious domains; outbound redirects (HTTP 302/301) from the IBM portal to non-organizational domains.
  • Logs: Web server or application access logs showing requests with redirect/next/url parameters set to external URLs not matching the organization's domain whitelist; repeated access from the same source IP to redirect-capable endpoints.
  • User Reports: End-user reports of being unexpectedly redirected to unfamiliar login pages after clicking links that appeared to originate from the IBM identity portal.

Mitigation and workarounds

IBM has released patches addressing this vulnerability; organizations should upgrade to versions beyond the affected ranges — IBM Verify Identity Access above 11.0.2, IBM Security Verify Access above 10.0.9.1, and their respective container editions. The IBM security bulletin (published July 8, 2026) provides specific remediation guidance and should be consulted for patch availability and upgrade instructions. As a configuration-based workaround, administrators should implement allowlist-based validation of redirect URLs at the application or reverse proxy layer to restrict redirects to trusted domains only (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM Security Verify Access (formerly ISAM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-1346HIGH7.8
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 08, 2026
CVE-2026-4938MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-5926MEDIUM6.5
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoApr 23, 2026
CVE-2026-8861MEDIUM5.3
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026
CVE-2026-7364LOW3.1
  • IBM Security Verify Access (formerly ISAM) logoIBM Security Verify Access (formerly ISAM)
  • cpe:2.3:a:ibm:security_verify_access
NoNoJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management