Metrics
Affected Vendors & Products
No advisories yet.
Solution
IBM strongly recommends addressing the vulnerability now. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<=v1.0.7Upgrade to v1.0.8. See [release notes]( https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.8) https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.8%29 . Rotate `JWT_SECRET_KEY`, `AUTH_ENCRYPTION_SECRET`, `DATABASE_URL`, `REDIS_URL`, and `BASIC_AUTH_PASSWORD` on any deployment running prior versions. Note: From version v1.0.8 on a more complex AUTH_ENCRYPTION_SECRET is required: Action required before upgrading: run the one-shot re-encryption script (mcpgateway/scripts/migrate_enc_secret.py) with the old and new keys while the gateway is stopped. See the full rotation guide at docs/docs/operations/auth-encryption-secret-rotation.md https://github.com/IBM/mcp-context-forge/blob/v1.0.8/docs/docs/operations/auth-encryption-secret-rotation.md for step-by-step instructions, deployment-specific commands, and special cases (Helm/Kubernetes, Python package consumers, rollback).
Workaround
None. IBM strongly recommends upgrading to the fixed version and rotating server credentials.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286052 |
|
Fri, 04 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters. | |
| Title | IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution | |
| First Time appeared |
Ibm
Ibm contextforge-mcp-gateway |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:ibm:contextforge-mcp-gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ibm
Ibm contextforge-mcp-gateway |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-04T16:24:45.432Z
Reserved: 2026-07-31T13:30:12.746Z
Link: CVE-2026-18486
No data.
Status : Received
Published: 2026-09-04T17:16:56.420
Modified: 2026-09-04T17:16:56.420
Link: CVE-2026-18486
No data.
OpenCVE Enrichment
Updated: 2026-09-04T18:45:03Z