Server-Side Request Forgery Vulnerability in IBM DataPower Gateway
CVE-2026-14521
4.9MEDIUM
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-14521?
IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 are vulnerable to a server-side request forgery (SSRF) issue. This vulnerability enables an authenticated attacker to craft and send unauthorized requests from the DataPower system itself. Such requests could potentially allow the attacker to enumerate network services or facilitate additional attacks, thereby posing a significant risk to the security and integrity of the networked environment.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6