📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global data_breach Government HIGH 1h Global malware Software Development CRITICAL 1h Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h Global data_breach Government HIGH 1h Global malware Software Development CRITICAL 1h Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h Global data_breach Government HIGH 1h Global malware Software Development CRITICAL 1h Global phishing Multiple Sectors HIGH 1h Global vulnerability Web Applications CRITICAL 2h Global apt Critical Infrastructure CRITICAL 2h Global ransomware Multiple sectors CRITICAL 2h Global supply_chain Software Development, IT Infrastructure, Technology CRITICAL 3h Global vulnerability,data_breach,general Technology, Industrial Control Systems, Telecommunications HIGH 4h Global general Consumer Electronics and Retail MEDIUM 6h Global supply_chain Software Development and Technology HIGH 6h
Vulnerabilities

CVE-2026-1343

High
CWE-918 — Weakness Type
Published: Apr 8, 2026  ·  Modified: Apr 14, 2026  ·  Source: NVD
CVSS v3
7.2
🔗 NVD Official
📄 Description (English)

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 allows an attacker to contact internal authentication endpoints which are protected by the Reverse Proxy.

🤖 AI Executive Summary

IBM Verify Identity Access Container and Security Verify Access versions 10.0-10.0.9.1 and 11.0-11.0.2 contain a Server-Side Request Forgery (SSRF) vulnerability allowing attackers to bypass reverse proxy protections and contact internal authentication endpoints. This vulnerability could enable unauthorized access to sensitive authentication systems and internal resources.

📄 Description (Arabic)

تسمح ثغرة Server-Side Request Forgery (SSRF) في منتجات IBM Verify بتجاوز آليات الحماية بالوكيل العكسي والوصول المباشر إلى نقاط نهاية المصادقة الداخلية. يمكن للمهاجمين استغلال هذه الثغرة للوصول إلى موارد داخلية حساسة وأنظمة المصادقة دون تفويض.

🤖 ملخص تنفيذي (AI)

حاويات IBM Verify Identity Access والإصدارات 10.0-10.0.9.1 و11.0-11.0.2 تحتوي على ثغرة SSRF تسمح للمهاجمين بتجاوز حماية الوكيل العكسي والوصول إلى نقاط نهاية المصادقة الداخلية. قد تمكن هذه الثغرة من الوصول غير المصرح به إلى الأنظمة الحساسة والموارد الداخلية.

🤖 AI Intelligence Analysis Analyzed: May 9, 2026 00:00
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
banking government telecom healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
7.0
/ 10.0
🔧 Remediation Steps (English)
Immediately upgrade IBM Verify Identity Access Container to version 11.0.3 or later and IBM Security Verify Access Container to version 10.0.10 or later. For non-containerized deployments, upgrade IBM Verify Identity Access to 11.0.3+ and IBM Security Verify Access to 10.0.10+. Implement network segmentation to restrict internal endpoint access and monitor reverse proxy logs for suspicious SSRF attempts.
🔧 خطوات المعالجة (العربية)
قم بالترقية الفورية لحاوية IBM Verify Identity Access إلى الإصدار 11.0.3 أو أحدث وحاوية IBM Security Verify Access إلى الإصدار 10.0.10 أو أحدث. للنشرات غير المحتوية على حاويات، قم بالترقية إلى 11.0.3+ و10.0.10+ على التوالي. طبق تقسيم الشبكة لتقييد الوصول إلى نقاط النهاية الداخلية ومراقبة سجلات الوكيل العكسي للكشف عن محاولات SSRF المريبة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 5.1.2 5.2.1
🔵 SAMA CSF
AC-3 AC-6 SI-4
🟡 ISO 27001:2022
A.6.1.1 A.13.1.1 A.14.2.1
📦 Affected Products / CPE 4 entries
ibm:security_verify_access
ibm:security_verify_access_container
ibm:verify_identity_access
ibm:verify_identity_access_container
📊 CVSS Score
7.2
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score7.2
CWECWE-918
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-04-08
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
7.0
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-918
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.