Skip to content
Threat Feed
critical advisory

Cross-Site Scripting Vulnerability in IBM DataPower Gateway

IBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 contain a reflected cross-site scripting (XSS) vulnerability allowing unauthenticated remote attackers to execute arbitrary JavaScript in the Web UI.

CVE search metadata

CVE search record: CVE-2026-14990. Severity: critical. CVSS: 9.3. KEV: no. Product: DataPower Gateway (10.6.0.0-10.6.0.10), DataPower Gateway (10.5.0.0-10.5.0.22, 10.6.0.0-10.6.0.10, 10.6.1-10.6.6, 11.0.0.0-11.0.0.2), DataPower Gateway (11.0.0.0-11.0.0.2). Brief: Cross-Site Scripting Vulnerability in IBM DataPower Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ibm-datapower-xss/

What's new

  • 1. added coverage for DataPower Gateway (11.0.0.0-11.0.0.2) Oct 8, 15:11 via nvd
  • 2. added coverage for DataPower Gateway (10.5.0.0-10.5.0.22, 10.6.0.0-10.6.0.10, 10.6.1-10.6.6, 11.0.0.0-11.0.0.2) Oct 8, 15:10 via nvd

IBM DataPower Gateway versions 10.6.0.0 through 10.6.0.10 are affected by a cross-site scripting (XSS) vulnerability within the product's Web UI. The vulnerability allows an unauthenticated remote attacker to inject malicious JavaScript code into the web interface. Because the gateway interface processes user input without sufficient sanitization, an attacker can execute code in the context of an authenticated user's session. This could result in unauthorized administrative actions, sensitive information disclosure, or credential theft by intercepting session tokens. This vulnerability is critical for organizations relying on the DataPower Gateway for API management and security, as a compromise of the administrative interface undermines the security posture of the protected backend services.

Impact

Successful exploitation allows for the execution of arbitrary JavaScript within the session of an authenticated user, such as an administrator. Potential consequences include the exfiltration of session cookies, modification of gateway configurations, and unauthorized access to managed API traffic. All deployments of IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 are at risk.

Recommendation

Prioritized actions for security and infrastructure teams:

  • Upgrade all instances of IBM DataPower Gateway to a version beyond 10.6.0.10 immediately.
  • Until patching is possible, restrict access to the DataPower Web UI management interface to trusted IP addresses using network-level access control lists (ACLs).
  • Monitor administrative audit logs for unusual access patterns or modifications performed in the Web UI.

Immediate actions

Upgrade IBM DataPower Gateway to version > 10.6.0.10

IT Operations 48h

Mitigations

Restrict Web UI access via network ACLs

immediate IT Operations

CVE-2026-14990