ZeroHour

CVE-2026-78573

niche

Default Credentials Enable Remote Admin Takeover of IBM ContextForge MCP Gateway

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

IBM ContextForge MCP Gateway versions 1.0.0 through 1.0.7 ship with default administrative credentials that are not forced to be changed. A remote attacker who can reach the gateway's management interface over the network can authenticate with these default credentials without any user interaction or prior privileges, gaining full administrative control of the gateway. Because the product brokers Model Context Protocol traffic between AI agents and backend tools/services, an attacker with admin access could reconfigure routing, access downstream connection details and credentials, and tamper with tool invocations. The issue carries a critical CVSS 3.1 score of 9.8, but there is no known public proof of concept and no evidence of exploitation in the wild to date.

What to do: Upgrade ContextForge MCP Gateway to the latest release from IBM (anything after 1.0.7, per IBM's advisory) and immediately replace the default administrative credentials if an upgrade cannot be applied right away. Restrict network access to the gateway's admin interface (VPN, allowlist, or internal-only placement) and verify no unauthenticated-origin admin logins appear in gateway logs. Because admin access can expose downstream tool connections, rotate any API keys, tokens, or service credentials configured on affected gateways.

Affected
IBM ContextForge MCP Gateway1.0.0 through 1.0.7
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments — No public install counts exist; the product is a recently released (1.0.x) enterprise AI-infrastructure gateway typically deployed in limited numbers inside corporate networks rather than broadly internet-exposed, so the true count is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

Vendors
ibm
Products
contextforge
Weakness
CWE-1392
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.