Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-14990: IBM DataPower Gateway lets attackers steal credentials via web UI

CVE-2026-14990 · published 3 days ago
Summary

Versions 10.6.0.0 through 10.6.0.10 of IBM DataPower Gateway can be tricked into running malicious JavaScript in its web interface. An attacker could use this to capture login information from users who are already signed in. Update to a patched version or apply the vendor’s recommended fix as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ibm datapower gateway 10.6.0 <= 10.6.0.10
Original advisory text
IBM DataPower Gateway affected by cross-site scripting
IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-14990 · MITRE
Track software like this
Free during beta