Remote Authorization Bypass in IBM DataPower Gateway
CVE-2026-16181
7.4HIGH
Key Information:
- Vendor
IBM
- Status
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-16181?
IBM DataPower Gateway versions 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 are susceptible to a remote authorization bypass. This vulnerability may allow unauthorized access by permitting attackers to circumvent security restrictions, thereby potentially exposing sensitive data and compromising system integrity. Users are advised to apply necessary updates and consult the vendor advisory to mitigate risks.
Affected Version(s)
DataPower Gateway 10.5.0 10.5.0.0 <= 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 <= 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 <= 10.6.6