IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

Project Subscriptions

Vendors Products
Contextforge Mcp Gateway Subscribe
Advisories

No advisories yet.

Fixes

Solution

IBM strongly recommends addressing the vulnerability now. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.9Upgrade to v1.0.10. See release notes. Additionally, ensure platform_admin_password, default_user_password, and basic_auth_password are set to strong, non-default values before enabling api_allow_basic_auth or mcpgateway_ui_enabled. Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description>


Workaround

On a default deployment, api_allow_basic_auth and mcpgateway_ui_enabled are both set to False, which prevents the default credentials from being exposed through an active authentication path. Operators who have not enabled either of these features are not immediately at risk. If upgrading is not immediately possible, ensure both features remain disabled until the password fields are set to strong, operator-defined values.

History

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
Title IBM ContextForge MCP Gateway is affected by use of default credentials
First Time appeared Ibm
Ibm contextforge Mcp Gateway
Weaknesses CWE-1392
CPEs cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm contextforge Mcp Gateway
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:42:36.717Z

Reserved: 2026-08-24T20:35:05.656Z

Link: CVE-2026-78573

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:16:59.987

Modified: 2026-09-10T22:16:59.987

Link: CVE-2026-78573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses