CVE-2026-1343
published 2026-04-08CVE-2026-1343: IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0…
PriorityP342high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
0.20%
9.8th percentile
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_verify_access | 10.0 – 10.0.9.1 | — |
| ibm | security_verify_access | 10.0.0 – 10.0.9.1 | — |
| ibm | security_verify_access_container | 10.0 – 10.0.9.1 | — |
| ibm | security_verify_access_container | 10.0.0.0 – 10.0.9.1 | — |
| ibm | verify_identity_access | 11.0 – 11.0.2 | — |
| ibm | verify_identity_access | 11.0.0.0 – 11.0.2.0 | — |
| ibm | verify_identity_access_container | 11.0 – 11.0.2 | — |
| ibm | verify_identity_access_container | 11.0.0.0 – 11.0.2.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Verify Identity Access Container server-side request forgery (CNNVD-202604-1896)
vuldb·2026-04-10·CVSS 7.2
CVE-2026-1343 [HIGH] IBM Verify Identity Access Container server-side request forgery (CNNVD-202604-1896)
A vulnerability was found in IBM Verify Identity Access Container, Security Verify Access Container, Verify Identity Access and Security Verify Access. It has been classified as critical. This impacts an unknown function. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-1343. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-249q-vrhp-j59w: IBM Verify Identity Access Container 11
ghsa_unreviewed·2026-04-08
CVE-2026-1343 [HIGH] CWE-918 GHSA-249q-vrhp-j59w: IBM Verify Identity Access Container 11
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-1342 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2026-1342 [HIGH] CVE-2026-1342 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1342 :
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
Source : NVD
## 7.9
Score
Published April 8, 2026
Severity HIGH
CNA Score 8.5
Affected Technologies
IBM Security Verify Access (formerly ISAM)
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Wiz
CVE-2026-1343 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2026-1343 [HIGH] CVE-2026-1343 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1343 :
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.
Source : NVD
## 7.2
Score
Published April 8, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
IBM Security Verify Access (formerly ISAM)
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.3
Exploitation Probability (EPSS) N/A
Affected packages and librarie
Wiz
CVE-2026-1346 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.5
CVE-2026-1346 [HIGH] CVE-2026-1346 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1346 :
IBM Security Verify Access (formerly ISAM) vulnerability analysis and mitigation
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution with unnecessary privileges than required.
Source : NVD
## 7.8
Score
Published April 8, 2026
Severity HIGH
CNA Score 9.3
Affected Technologies
IBM Security Verify Access (formerly ISAM)
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
2026-04-08
Published