Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-14502 2026-10-08

IBM DataPower Gateway Flaw Lets Remote Attackers Gain Admin Access via Empty LDAP Passwords (CVE-2026-14502)

"CVE-2026-14502 is a critical (CVSS 9.8) authentication flaw in several IBM DataPower Gateway release lines that could let a remote, unauthenticated attacker get administrative access because empty passwords are not…"

CVE-2026-14502 is a critical (CVSS 9.8) authentication flaw in several IBM DataPower Gateway release lines that could let a remote, unauthenticated attacker get administrative access because empty passwords are not rejected during LDAP authentication.

What Is It

According to the NVD record, which IBM PSIRT submitted, IBM DataPower Gateway does not reject empty passwords during LDAP authentication. A remote attacker could use this to obtain administrative access. The weakness is classified as CWE-287 (Improper Authentication).

NVD published the CVE on 2026-10-08. Its status is "Awaiting Analysis," so NVD has not yet completed its own enrichment of the record.

Why It Matters

IBM rates this flaw CVSS 3.1 base score 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In practice, that means:

Administrative access to a gateway appliance gives an attacker control over a device that sits in the traffic path. At the time of writing, the supplied CISA Known Exploited Vulnerabilities (KEV) data has no entry for CVE-2026-14502. Active exploitation is not confirmed by KEV.

What's Vulnerable

IBM lists the following DataPower Gateway versions as affected:

Product line Affected versions
DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.22
DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.10
DataPower Gateway 10.6CD 10.6.1 through 10.6.6
DataPower Gateway 11.0.0 11.0.0.0 through 11.0.0.2

The issue is in LDAP authentication. Deployments that authenticate users against LDAP are the ones the vulnerable code path applies to.

Patch Status

The NVD record does not list fixed versions or specific remediation steps. IBM has published a security bulletin for this issue, linked below. Administrators running any affected version should:

Because there is no CISA KEV entry, no federal required action or due date applies to this CVE at this time.

Sources