IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
History

Fri, 11 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm contextforge-mcp-gateway
Vendors & Products Ibm contextforge-mcp-gateway

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
Title IBM ContextForge MCP Gateway is affected by use of default credentials
First Time appeared Ibm
Ibm contextforge Mcp Gateway
Weaknesses CWE-1392
CPEs cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm contextforge Mcp Gateway
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-09-10T21:42:36.717Z

Updated: 2026-09-10T21:42:36.717Z

Reserved: 2026-08-24T20:35:05.656Z

Link: CVE-2026-78573

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:16:59.987

Modified: 2026-09-10T22:16:59.987

Link: CVE-2026-78573

cve-icon Redhat

No data.