SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18489

HIGH · CVSS 7.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The IBM ContextForge MCP Gateway's Translate utility versions 1.0.8 and earlier are vulnerable to a session management flaw that allows remote attackers to access sensitive information from other user sessions. This exposure could lead to unauthorized data disclosure, making it critical for organizations using this utility to prioritize patching or mitigating this vulnerability to protect sensitive information. Users of the affected product should take immediate action to secure their systems against potential exploitation.

CVE
CVE-2026-18489
Severity
HIGH
CVSS
7.4
EPSS
0.26%

Original NVD Description

IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.

Related CVEs

Other vulnerabilities affecting the same vendor(s)