Server-Side Request Forgery Vulnerability in IBM ContextForge MCP Gateway
CVE-2026-77822

8.2HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 September 2026

What is CVE-2026-77822?

The vulnerability in IBM's ContextForge MCP Gateway could be exploited by remote authenticated attackers to access sensitive information. This is achieved through a server-side request forgery mechanism that takes advantage of DNS rebinding, potentially compromising the confidentiality of data and exposing the system to further attacks. Organizations using this product should consider applying relevant patches to enhance their security posture and mitigate risks associated with this vulnerability.

Affected Version(s)

ContextForge MCP Gateway <= v1.0.8

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.