CVE-2026-78573
9.8IBM · ContextForge MCP Gateway
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 contains a vulnerability involving the use of default credentials, which allows unauthenticated remote attackers to gain administrative access.
Executive summary
A critical vulnerability in the IBM ContextForge MCP Gateway allows unauthenticated remote attackers to obtain full administrative control by exploiting default credentials.
Vulnerability
The application utilizes default credentials for administrative accounts, which can be leveraged by unauthenticated remote attackers to bypass security controls and gain full administrative privileges. This flaw is categorized under CWE-1392: Use of Default Credentials.
Business impact
Successful exploitation of this vulnerability grants an attacker complete administrative access to the ContextForge MCP Gateway, leading to a total compromise of system confidentiality, integrity, and availability. With a CVSS score of 9.8, this represents a critical risk that could result in unauthorized data exfiltration, service disruption, and the potential for lateral movement within the environment.
Remediation
Immediate Action: Upgrade the IBM ContextForge MCP Gateway to version 1.0.10 or later. Ensure that all administrative passwords, including default and basic authentication credentials, are changed to strong, unique values before enabling any web-based management interfaces.
Proactive Monitoring: Review system and application access logs for any irregular administrative logins or authentication failures originating from unexpected IP addresses.
Compensating Controls: Implement network-level access controls or a Web Application Firewall to restrict access to the management gateway interface to authorized management subnets only until the patch is applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a severe risk due to the ease of exploitation and the high level of access granted to attackers. Organizations must prioritize upgrading to version 1.0.10 immediately and perform a mandatory audit of all administrative credentials to ensure that no default values remain in the production environment.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section