7.4
CVE-2026-18489
- EPSS 0.26%
- Veröffentlicht 04.09.2026 16:23:08
- Zuletzt bearbeitet 15.09.2026 15:04:09
- Erkennungen
IBM ContextForge Translate is affected by cross-client credential context confusion
IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Contextforge SwPlatform python Version <= 1.0.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.173 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-488 Exposure of Data Element to Wrong Session
The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.
https://www.ibm.com/support/pages/node/7286056