PT-2026-108005 · Ibm · Datapower Gateway 10.5.0+3

CVE-2026-14502

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14502

Affected Products

Datapower Gateway 10.5.0
Datapower Gateway 10.6.0
Datapower Gateway 10.6Cd
Datapower Gateway 11.0.0