ZeroHour

CVE-2026-18489

niche

Cross-Session Information Disclosure in IBM ContextForge MCP Gateway Translate Utility

CVSS 3.1
7.4 high
EPSS
<1%p17
Published
()
Modified
AI analysis

IBM ContextForge MCP Gateway's Translate utility, version 1.0.8 and earlier, contains a flaw (CWE-488) in which data elements belonging to one session are exposed to the wrong session. A remote attacker can trigger the issue over the network without authentication, although the high attack complexity (AC:H) means successful exploitation requires favorable conditions, such as landing in a state where another session's data is served. A successful attacker gains access to sensitive information from other users' sessions, and the CVSS score of 7.4 indicates potentially high confidentiality and integrity impact. Any deployment of IBM ContextForge MCP Gateway running the affected Translate utility is exposed, with risk concentrated in multi-tenant or multi-user gateways where cross-session leakage affects other users. As of now there is no known public proof-of-concept, no CISA KEV listing, and EPSS puts the 30-day exploitation probability at only 0.3%.

What to do: Upgrade the Translate utility in IBM ContextForge MCP Gateway to a version later than 1.0.8 as soon as IBM publishes a fixed release, and check the IBM security advisory for the exact fixed version. In the meantime, minimize exposure of the gateway to untrusted networks, review whether multi-user/multi-tenant sessions share the Translate component, and monitor logs for signs of responses or data being served across sessions.

Affected
IBM ContextForge MCP Gateway - Translate utility<= 1.0.8
Estimated exposure
nicheunknown; plausibly low thousands of self-hosted organizational deployments at most — ContextForge is a recently introduced, specialized open-source Model Context Protocol gateway deployed per organization rather than as mass-market software, and the data provides no public install counts or internet-exposed scan figures,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.

Vendors
ibm
Products
contextforge
Weakness
CWE-488
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.