SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18486

HIGH · CVSS 8.8 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM ContextForge MCP Gateway versions up to 1.0.7 are vulnerable to a security flaw that enables remote authenticated attackers to exploit improper validation of jq filters, potentially leading to the exposure of sensitive credentials and privilege escalation. Organizations using this gateway should prioritize patching to mitigate the risk of unauthorized access and data breaches. Immediate action is recommended for those managing sensitive environments or relying on this software for critical operations.

CVE
CVE-2026-18486
Severity
HIGH
CVSS
8.8
EPSS
0.33%

Original NVD Description

IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.

Related CVEs

Other vulnerabilities affecting the same vendor(s)