CVE-2026-14502 is a critical (CVSS 9.8) authentication flaw in several IBM DataPower Gateway release lines that could let a remote, unauthenticated attacker get administrative access because empty passwords are not rejected during LDAP authentication.
What Is It
According to the NVD record, which IBM PSIRT submitted, IBM DataPower Gateway does not reject empty passwords during LDAP authentication. A remote attacker could use this to obtain administrative access. The weakness is classified as CWE-287 (Improper Authentication).
NVD published the CVE on 2026-10-08. Its status is "Awaiting Analysis," so NVD has not yet completed its own enrichment of the record.
Why It Matters
IBM rates this flaw CVSS 3.1 base score 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In practice, that means:
- Network-reachable: the attacker does not need local access.
- Low attack complexity: no special conditions are required.
- No privileges or user interaction: the attacker does not need an account or a victim's help.
- High impact: a successful attack fully compromises confidentiality, integrity and availability.
Administrative access to a gateway appliance gives an attacker control over a device that sits in the traffic path. At the time of writing, the supplied CISA Known Exploited Vulnerabilities (KEV) data has no entry for CVE-2026-14502. Active exploitation is not confirmed by KEV.
What's Vulnerable
IBM lists the following DataPower Gateway versions as affected:
| Product line | Affected versions |
|---|---|
| DataPower Gateway 10.5.0 | 10.5.0.0 through 10.5.0.22 |
| DataPower Gateway 10.6.0 | 10.6.0.0 through 10.6.0.10 |
| DataPower Gateway 10.6CD | 10.6.1 through 10.6.6 |
| DataPower Gateway 11.0.0 | 11.0.0.0 through 11.0.0.2 |
The issue is in LDAP authentication. Deployments that authenticate users against LDAP are the ones the vulnerable code path applies to.
Patch Status
The NVD record does not list fixed versions or specific remediation steps. IBM has published a security bulletin for this issue, linked below. Administrators running any affected version should:
- check the IBM advisory for fixed releases and any interim guidance
- prioritize remediation because of the critical, unauthenticated, network-reachable nature of the flaw
Because there is no CISA KEV entry, no federal required action or due date applies to this CVE at this time.