CVE-2026-78573: IBM ContextForge MCP Gateway is affected by use of default credentials
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.
Other sources
MCP Context Forge could allow a remote attacker to gain administrative access due to the use of default credentials.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ContextForge MCP Gatewayto a version that resolves this vulnerability.Fixed in v1.0.10 - Configuration
Before enabling api_allow_basic_auth or mcpgateway_ui_enabled, set platform_admin_password to a strong, non-default value.
IBM ContextForge MCP Gateway platform_admin_password = strong, non-default value - Configuration
Before enabling api_allow_basic_auth or mcpgateway_ui_enabled, set default_user_password to a strong, non-default value.
IBM ContextForge MCP Gateway default_user_password = strong, non-default value - Configuration
Before enabling api_allow_basic_auth or mcpgateway_ui_enabled, set basic_auth_password to a strong, non-default value.
IBM ContextForge MCP Gateway basic_auth_password = strong, non-default value
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit it without authentication or user interaction, as indicated by the network attack vector and no required privileges.
Which releases are affected?
IBM ContextForge MCP Gateway versions 1.0.0 through 1.0.7 are affected.
What access could an attacker obtain?
Successful exploitation could give a remote attacker administrative access to the gateway.