PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13258 IBM CVE debrief

IBM DataPower Gateway is vulnerable to cross-site scripting, allowing authenticated users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within trusted sessions. Defenders and administrators should assess exposure and prioritize patching to prevent potential credentials disclosure. The vulnerability affects various versions of IBM DataPower Gateway, including 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2.

Vendor
IBM
Product
DataPower Gateway 10.6CD
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders and administrators of IBM DataPower Gateway instances, especially those with authenticated user access to the Web UI, should assess exposure and prioritize patching to prevent potential credentials disclosure within trusted sessions.

Why it matters

Defenders should prioritize verifying exposure of DataPower Gateway instances and assess the risk of credentials disclosure within trusted sessions due to the cross-site scripting vulnerability.

  • Potential credentials disclosure within trusted sessions
  • Alteration of intended Web UI functionality
  • Risk of unauthorized access to sensitive data
  • Need for verification of exposure and patch application

Technical summary

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 are vulnerable to cross-site scripting, allowing authenticated users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within trusted sessions. The vulnerability can be exploited by an authenticated user, and defenders should prioritize verifying exposure of DataPower Gateway instances and assess the risk of credentials disclosure within trusted sessions.

Defensive priority

Defenders should prioritize verifying exposure of DataPower Gateway instances, especially those with authenticated user access to the Web UI, and assess the risk of credentials disclosure within trusted sessions.

Recommended defensive actions

  • Verify exposure of DataPower Gateway instances, especially those with authenticated user access to the Web UI
  • Assess the risk of credentials disclosure within trusted sessions
  • Review and apply patches from IBM as available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and a reference to an IBM support page for patch information. The vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within trusted sessions. Defenders should verify exposure of DataPower Gateway instances, especially those with authenticated user access to the Web UI, and assess the risk of credentials disclosure within trusted sessions. The source item and CVE

Sources and references

Verified primary and authoritative sources

  • CVE-2026-13258 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-13258

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-13258 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13258

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • IBM DataPower Gateway Cross-Site Scripting

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/13xxx/CVE-2026-13258.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.ibm.com/support/pages/node/7289775

    Supplemental source - vendor-advisory, patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.