CVE-2026-18489
nicheCross-Session Information Disclosure in IBM ContextForge MCP Gateway Translate Utility
IBM ContextForge MCP Gateway's Translate utility, version 1.0.8 and earlier, contains a flaw (CWE-488) in which data elements belonging to one session are exposed to the wrong session. A remote attacker can trigger the issue over the network without authentication, although the high attack complexity (AC:H) means successful exploitation requires favorable conditions, such as landing in a state where another session's data is served. A successful attacker gains access to sensitive information from other users' sessions, and the CVSS score of 7.4 indicates potentially high confidentiality and integrity impact. Any deployment of IBM ContextForge MCP Gateway running the affected Translate utility is exposed, with risk concentrated in multi-tenant or multi-user gateways where cross-session leakage affects other users. As of now there is no known public proof-of-concept, no CISA KEV listing, and EPSS puts the 30-day exploitation probability at only 0.3%.
What to do: Upgrade the Translate utility in IBM ContextForge MCP Gateway to a version later than 1.0.8 as soon as IBM publishes a fixed release, and check the IBM security advisory for the exact fixed version. In the meantime, minimize exposure of the gateway to untrusted networks, review whether multi-user/multi-tenant sessions share the Translate component, and monitor logs for signs of responses or data being served across sessions.
| IBM ContextForge MCP Gateway - Translate utility | <= 1.0.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.
- Vendors
- ibm
- Products
- contextforge
- Weakness
- CWE-488
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.