{"api_version":"1","generated_at":"2026-09-11T00:21:17+00:00","cve":"CVE-2026-78573","urls":{"html":"https://cve.report/CVE-2026-78573","api":"https://cve.report/api/cve/CVE-2026-78573.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78573","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78573"},"summary":{"title":"IBM ContextForge MCP Gateway is affected by use of default credentials","description":"IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-09-10 22:16:59","updated_at":"2026-09-10 22:16:59"},"problem_types":["CWE-1392","CWE-1392 CWE-1392 Use of Default Credentials"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286834","name":"https://www.ibm.com/support/pages/node/7286834","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78573","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78573","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"ContextForge MCP Gateway","version":"affected 1.0.0 1.0.7 semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly recommends addressing the vulnerability now.\nProduct(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.9Upgrade to v1.0.10. See release notes. Additionally, ensure platform_admin_password, default_user_password, and basic_auth_password are set to strong, non-default values before enabling api_allow_basic_auth or mcpgateway_ui_enabled. Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description>","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"On a default deployment, api_allow_basic_auth and mcpgateway_ui_enabled are both set to False, which prevents the default credentials from being exposed through an active authentication path. Operators who have not enabled either of these features are not immediately at risk. If upgrading is not immediately possible, ensure both features remain disabled until the password fields are set to strong, operator-defined values.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:contextforge_mcp_gateway:1.0.7:*:*:*:*:*:*:*"],"product":"ContextForge MCP Gateway","vendor":"IBM","versions":[{"lessThanOrEqual":"1.0.7","status":"affected","version":"1.0.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.</p>"}],"value":"IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1392","description":"CWE-1392 Use of Default Credentials","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-10T21:42:36.717Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7286834"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p><strong>IBM strongly recommends addressing the vulnerability now.</strong></p><div><table><tbody><tr><td><strong>Product(s)</strong></td><td><strong>Version(s) number and/or range </strong></td><td><strong>Remediation/Fix/Instructions</strong></td></tr><tr><td>IBM ContextForge MCP Gateway</td><td>v1.0.0 - v1.0.9</td><td>Upgrade to v1.0.10. See <a href=\"https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.10\" rel=\"nofollow\">release notes</a>. Additionally, ensure <code>platform_admin_password</code>, <code>default_user_password</code>, and <code>basic_auth_password</code> are set to strong, non-default values before enabling <code>api_allow_basic_auth</code> or <code>mcpgateway_ui_enabled</code>.</td></tr></tbody></table></div><p> Note: &lt;Component A / B names&gt; are bundled with &lt;Product profile name&gt; to provide &lt;feature / function description&gt;</p><p></p>"}],"value":"IBM strongly recommends addressing the vulnerability now.\nProduct(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.9Upgrade to v1.0.10. See release notes. Additionally, ensure platform_admin_password, default_user_password, and basic_auth_password are set to strong, non-default values before enabling api_allow_basic_auth or mcpgateway_ui_enabled. Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description>"}],"title":"IBM ContextForge MCP Gateway is affected by use of default credentials","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>On a default deployment, <code>api_allow_basic_auth</code> and <code>mcpgateway_ui_enabled</code> are both set to <code>False</code>, which prevents the default credentials from being exposed through an active authentication path. Operators who have not enabled either of these features are not immediately at risk. If upgrading is not immediately possible, ensure both features remain disabled until the password fields are set to strong, operator-defined values.</p>"}],"value":"On a default deployment, api_allow_basic_auth and mcpgateway_ui_enabled are both set to False, which prevents the default credentials from being exposed through an active authentication path. Operators who have not enabled either of these features are not immediately at risk. If upgrading is not immediately possible, ensure both features remain disabled until the password fields are set to strong, operator-defined values."}]}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-78573","datePublished":"2026-09-10T21:42:36.717Z","dateReserved":"2026-08-24T20:35:05.656Z","dateUpdated":"2026-09-10T21:42:36.717Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-10 22:16:59","lastModifiedDate":"2026-09-10 22:16:59","problem_types":["CWE-1392","CWE-1392 CWE-1392 Use of Default Credentials"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78573","Ordinal":"1","Title":"IBM ContextForge MCP Gateway is affected by use of default crede","CVE":"CVE-2026-78573","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78573","Ordinal":"1","NoteData":"IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.","Type":"Description","Title":"IBM ContextForge MCP Gateway is affected by use of default crede"}]}}}