Description
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
Published: 2026-09-10
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Administrative Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because IBM ContextForge MCP Gateway versions 1.0.0 through 1.0.7 store predictable default credential values—including platform_admin_password, default_user_password, and basic_auth_password—in their configuration. An attacker who can reach the gateway’s authentication interface can authenticate as a full administrator using these credentials, gaining unrestricted administrative access. This flaw corresponds to CWE-1392 and is reflected in a CVSS score of 9.8, indicating a critical risk to confidentiality, integrity, and availability of the gateway and any services it exposes.

Affected Systems

Vulnerable installations include IBM ContextForge MCP Gateway versions 1.0.0 to 1.0.7, which contain hard‑coded default passwords and enable authentication paths that allow those credentials to be used. The fix in v1.0.10 removes these defaults and requires that operators set platform_admin_password, default_user_password, and basic_auth_password to strong, non‑default values before enabling any authentication feature such as api_allow_basic_auth or mcpgateway_ui_enabled. Until upgraded or manually reconfigured, systems running 1.0.0-1.0.7 remain at risk.

Risk and Exploitability

An adversary can exploit the vulnerability by sending a login request to the gateway’s API or UI endpoint, supplying the known default credentials. Because no additional authentication checks or rate limiting are documented, the attack can be performed remotely over the network with little effort. The CVSS score of 9.8 underscores the severity, and the lack of an EPSS score or KEV listing does not reduce the likelihood that attackers will target this gap. Operators should treat this as a high‑risk exposure needing prompt action.

Generated by OpenCVE AI on September 11, 2026 at 04:19 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.9Upgrade to v1.0.10. See release notes. Additionally, ensure platform_admin_password, default_user_password, and basic_auth_password are set to strong, non-default values before enabling api_allow_basic_auth or mcpgateway_ui_enabled. Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description>


Vendor Workaround

On a default deployment, api_allow_basic_auth and mcpgateway_ui_enabled are both set to False, which prevents the default credentials from being exposed through an active authentication path. Operators who have not enabled either of these features are not immediately at risk. If upgrading is not immediately possible, ensure both features remain disabled until the password fields are set to strong, operator-defined values.


OpenCVE Recommended Actions

  • Upgrade to IBM ContextForge MCP Gateway v1.0.10 or later.
  • Change platform_admin_password, default_user_password, and basic_auth_password to strong, non‑default values.
  • If an upgrade is not immediately possible, keep api_allow_basic_auth and mcpgateway_ui_enabled disabled until the password fields have been replaced with strong values.

Generated by OpenCVE AI on September 11, 2026 at 04:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm contextforge-mcp-gateway
Vendors & Products Ibm contextforge-mcp-gateway

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
Title IBM ContextForge MCP Gateway is affected by use of default credentials
First Time appeared Ibm
Ibm contextforge Mcp Gateway
Weaknesses CWE-1392
CPEs cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.7:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm contextforge Mcp Gateway
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Contextforge-mcp-gateway Contextforge Mcp Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:42:36.717Z

Reserved: 2026-08-24T20:35:05.656Z

Link: CVE-2026-78573

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:16:59.987

Modified: 2026-09-10T22:16:59.987

Link: CVE-2026-78573

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:15:16Z

Weaknesses