CVE-2026-78573
nicheDefault Credentials Enable Remote Admin Takeover of IBM ContextForge MCP Gateway
IBM ContextForge MCP Gateway versions 1.0.0 through 1.0.7 ship with default administrative credentials that are not forced to be changed. A remote attacker who can reach the gateway's management interface over the network can authenticate with these default credentials without any user interaction or prior privileges, gaining full administrative control of the gateway. Because the product brokers Model Context Protocol traffic between AI agents and backend tools/services, an attacker with admin access could reconfigure routing, access downstream connection details and credentials, and tamper with tool invocations. The issue carries a critical CVSS 3.1 score of 9.8, but there is no known public proof of concept and no evidence of exploitation in the wild to date.
What to do: Upgrade ContextForge MCP Gateway to the latest release from IBM (anything after 1.0.7, per IBM's advisory) and immediately replace the default administrative credentials if an upgrade cannot be applied right away. Restrict network access to the gateway's admin interface (VPN, allowlist, or internal-only placement) and verify no unauthenticated-origin admin logins appear in gateway logs. Because admin access can expose downstream tool connections, rotate any API keys, tokens, or service credentials configured on affected gateways.
| IBM ContextForge MCP Gateway | 1.0.0 through 1.0.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
- Vendors
- ibm
- Products
- contextforge
- Weakness
- CWE-1392
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.