
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7364 is an open redirect vulnerability affecting IBM Verify Identity Access and IBM Security Verify Access products, including their container variants. A remote attacker can exploit this flaw to redirect victims to arbitrary websites, facilitating phishing attacks. Affected versions include IBM Verify Identity Access 11.0 through 11.0.2, IBM Security Verify Access 10.0 through 10.0.9.1, and their respective container editions. The vulnerability was published on July 17, 2026, with a patch made available by IBM on July 8, 2026. It carries a CVSS v3.1 base score of 3.1 (Low) (IBM Advisory, GitHub Advisory).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), where the application accepts user-controlled input specifying an external link and uses it in a redirect without adequate validation. An unauthenticated remote attacker can craft a specially crafted HTTP request that causes the application to redirect a victim's browser to an arbitrary, attacker-controlled website. Exploitation requires user interaction (the victim must follow the malicious link) and has high attack complexity, limiting its practical reach. No public proof-of-concept code or detailed technical write-ups have been identified at this time (IBM Advisory, GitHub Advisory).
Successful exploitation primarily enables phishing attacks by redirecting authenticated or unauthenticated users from a trusted IBM identity management portal to an attacker-controlled site, potentially harvesting credentials or delivering malware. The confidentiality impact is rated Low, with no direct integrity or availability impact. Because the affected products are identity and access management platforms, credential theft via phishing could have downstream consequences including unauthorized access to protected resources (IBM Advisory, GitHub Advisory).
redirect, next, url, or similar query parameters used in authentication flows).https://victim-ibm-portal.example.com/login?redirect=https://attacker.example.com).IBM has released patches addressing this vulnerability; organizations should upgrade to versions beyond the affected ranges — IBM Verify Identity Access above 11.0.2, IBM Security Verify Access above 10.0.9.1, and their respective container editions. The IBM security bulletin (published July 8, 2026) provides specific remediation guidance and should be consulted for patch availability and upgrade instructions. As a configuration-based workaround, administrators should implement allowlist-based validation of redirect URLs at the application or reverse proxy layer to restrict redirects to trusted domains only (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."