CVE-2026-18486

Summary

IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.

Affected Software

VendorProductVersion RangeStatus
IBMContextForge MCP Gateway<= v1.0.7affected

Weaknesses

  • CWE-200: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Workarounds

None. IBM strongly recommends upgrading to the fixed version and rotating server credentials.

References