CVE-2026-14502
Received Received - Intake

Remote LDAP Authentication Bypass in IBM DataPower Gateway

Vulnerability report for CVE-2026-14502, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: IBM Corporation

Description

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
IBM DataPower Gateway 10.6CD 10.6.1
IBM DataPower Gateway 10.6.0 10.6.0.0
IBM DataPower Gateway 11.0.0 11.0.0.0
IBM DataPower Gateway 10.5.0 10.5.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a remote attacker to gain administrative access to IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 by exploiting a failure to reject empty passwords during LDAP authentication.

Detection Guidance

To detect this vulnerability, check if IBM DataPower Gateway versions 10.5.0.0-10.5.0.22, 10.6.1-10.6.6, 10.6.0.0-10.6.0.10, or 11.0.0.0-11.0.0.2 are configured with LDAP authentication allowing empty passwords. Review authentication logs for failed login attempts or unusual access patterns. Verify LDAP server settings to ensure empty passwords are not accepted.

Impact Analysis

An attacker could exploit this to gain full administrative control over the affected IBM DataPower Gateway systems, potentially leading to unauthorized access, data breaches, or system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR, HIPAA, and other regulations that mandate strict access controls and data protection measures.

Mitigation Strategies

Disable LDAP authentication or ensure empty passwords are rejected. Update IBM DataPower Gateway to a patched version. Review and restrict administrative access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14502. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart