CVE-2026-18489: IBM ContextForge Translate is affected by cross-client credential context confusion
IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not expose the IBM ContextForge Translate service in any production capacity; it is intended only for local, single-session development use.
Event History
Frequently Asked Questions
Which deployments are affected?
IBM ContextForge MCP Gateway - Translate utility / IBM ContextForge Translate versions up to and including 1.0.8 are identified as affected.
Can this be exploited remotely without authentication or user interaction?
Yes. The supplied vector indicates network access, no required privileges, and no user interaction, although exploitation has high attack complexity.
What is the impact of a successful exploit?
A remote attacker could obtain sensitive information belonging to other sessions because data elements may be exposed to the wrong session. The provided vector indicates high confidentiality and integrity impact, with no availability impact.