CVE-2026-13277
IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-601
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- IBM Verify Identity Access
- IBM Security Verify Access
- IBM Verify Identity Access Container
- IBM Security Verify Access Container
Weakness type
Related vulnerabilities
- CVE-2026-6795 — Open Redirect in DivvyDrive Information Technologies' DivvyDrive
- CVE-2026-54588 — Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
- CVE-2026-53662 — immich: One-click account takeover via XSS in login page continue redirect
- CVE-2026-43941 — Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click
- CVE-2026-61451 — Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
- CVE-2026-8323 — Open Redirect in Armiya Information Technologies' Access Control System
- CVE-2026-71428 — unstructured: Server-Side Request Forgery in the URL-based partitioning
- CVE-2026-54072 — Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL