IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286052 |
|
History
Fri, 04 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters. | |
| Title | IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution | |
| First Time appeared |
Ibm
Ibm contextforge-mcp-gateway |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:ibm:contextforge-mcp-gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm contextforge-mcp-gateway |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-09-04T16:24:45.432Z
Updated: 2026-09-04T16:24:45.432Z
Reserved: 2026-07-31T13:30:12.746Z
Link: CVE-2026-18486
No data.
Status : Awaiting Analysis
Published: 2026-09-04T17:16:56.420
Modified: 2026-09-08T14:17:08.940
Link: CVE-2026-18486
No data.