CVE-2026-14521
Received
Received - Intake
Server-Side Request Forgery in IBM DataPower Gateway
Vulnerability report for CVE-2026-14521, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: IBM Corporation
Description
Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2Β is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| IBM | DataPower | Gateway 10.6CD 10.6.1 |
| IBM | DataPower | Gateway 10.6.0 10.6.0.0 |
| IBM | DataPower | Gateway 11.0.0 11.0.0.0 |
| IBM | DataPower | Gateway 10.5.0 10.5.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-918 | The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. |