CVE-2026-18486
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | ContextForge MCP Gateway | <= v1.0.7 | affected |
Weaknesses
- CWE-200: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Workarounds
None. IBM strongly recommends upgrading to the fixed version and rotating server credentials.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.