CVE-2026-18489
Received Received - Intake

IBM ContextForge MCP Gateway Session Data Exposure Vulnerability

Vulnerability report for CVE-2026-18489, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: IBM Corporation

Description

IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm contextforge_mcp_gateway to 1.0.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-488 The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM ContextForge MCP Gateway - Translate utility version 1.0.8 or earlier has a vulnerability where a remote attacker could access sensitive information from other sessions due to incorrect data exposure across sessions.

Detection Guidance

This vulnerability involves sensitive information exposure due to improper session handling in IBM ContextForge MCP Gateway. Detection requires monitoring network traffic for unauthorized data access between sessions. Check application logs for unusual session data exposure events. Inspect network traffic for unencrypted sensitive data transmission. Validate session isolation mechanisms in the MCP Gateway configuration.

Impact Analysis

This vulnerability could allow unauthorized access to sensitive data from other users or sessions, potentially leading to data breaches, information leaks, or further exploitation of affected systems.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other privacy regulations due to unauthorized data exposure, potentially resulting in legal penalties, fines, or reputational damage.

Mitigation Strategies

Update IBM ContextForge MCP Gateway to the latest version beyond 1.0.8 to address the session data exposure issue. Restrict network access to the Translate utility to prevent unauthorized remote access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18489. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart