Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-14990: IBM DataPower Gateway lets attackers steal credentials via web UI
CVE-2026-14990 · published 3 days ago
Summary
Versions 10.6.0.0 through 10.6.0.10 of IBM DataPower Gateway can be tricked into running malicious JavaScript in its web interface. An attacker could use this to capture login information from users who are already signed in. Update to a patched version or apply the vendor’s recommended fix as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | datapower gateway 10.6.0 | <= 10.6.0.10 |
Original advisory text
IBM DataPower Gateway affected by cross-site scripting
IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta