CVE-2026-78573

Summary

IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

Affected Software

VendorProductVersion RangeStatus
IBMContextForge MCP Gateway1.0.0 <= 1.0.7affected

Weaknesses

  • CWE-1392: CWE-1392 Use of Default Credentials

Workarounds

On a default deployment, api_allow_basic_auth and mcpgateway_ui_enabled are both set to False, which prevents the default credentials from being exposed through an active authentication path. Operators who have not enabled either of these features are not immediately at risk. If upgrading is not immediately possible, ensure both features remain disabled until the password fields are set to strong, operator-defined values.

References