CVE-2026-18486: IBM ContextForge MCP Gateway <=1.0.7 jq Filter Credential Theft
CVE-2026-18486 Published on September 4, 2026
IBM ContextForge MCP Gateway is affected by credential disclosure and privilege escalation via jq filter execution
IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.
Vulnerability Analysis
CVE-2026-18486 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-18486 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-18486
Want to know whenever a new CVE is published for IBM Contextforge Mcp Gateway? stack.watch will email you.