Full Report
IBM security advisory (AV26-1022)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in IBM DataPower Gateway and Langflow OSS
## CVE Details
- **CVE ID:** CVE-2026-14990 (and others referenced via IBM bulletins)
- **CVSS Score:** Variable (Consult individual bulletins for specific scores)
- **CWE:** CWE-79 (Cross-site Scripting), among others referenced.
## Affected Systems
- **Products:**
- IBM DataPower Gateway (10.5.0, 10.6.0, 10.6CD, 11.0.0)
- Langflow OSS
- **Versions:**
- DataPower Gateway: $\le$ 10.5.0.22, $\le$ 10.6.0.10, $\le$ 10.6.6, $\le$ 11.0.0.2
- Langflow OSS: 1.0.0 to 1.12.2
- **Configurations:** Systems running affected versions with administrative web interfaces or user-input processing enabled.
## Vulnerability Description
IBM DataPower Gateway is susceptible to Cross-Site Scripting (XSS). This flaw allows an attacker to embed arbitrary JavaScript code within the WebGUI, which could be executed in a victim's browser session. Additionally, Langflow OSS is affected by multiple vulnerabilities (technical specifics vary by CVE) that could compromise the integrity and security of the AI workflow orchestration.
## Exploitation
- **Status:** Not exploited (No reports of active exploitation in the wild as of the advisory date).
- **Complexity:** Low to Medium.
- **Attack Vector:** Network.
## Impact
- **Confidentiality:** Partial (Potential for session hijacking/cookie theft via XSS).
- **Integrity:** Partial (Unauthorized actions performed in the context of the user).
- **Availability:** Low to None (Depending on the specific CVE in Langflow OSS).
## Remediation
### Patches
IBM recommends upgrading to the following versions or higher:
- **DataPower Gateway 10.5.0:** Apply 10.5.0.23 or later.
- **DataPower Gateway 10.6.0:** Apply 10.6.0.11 or later.
- **DataPower Gateway 10.6CD:** Apply 10.6.7 or later.
- **DataPower Gateway 11.0.0:** Apply 11.0.0.3 or later.
- **Langflow OSS:** Update to a version beyond 1.12.2 as specified in the IBM security bulletin.
### Workarounds
- For XSS: Ensure strict access controls to the WebGUI and avoid clicking untrusted links while authenticated to the management console.
- Disable unnecessary services or administrative interfaces on public-facing networks.
## Detection
- **Indicators of Compromise:** Unusual administrative logs, unexpected JavaScript execution errors in the browser console, or unauthorized configuration changes.
- **Detection methods and tools:** Utilize web application firewalls (WAF) to detect XSS patterns. Regularly audit management logs for unauthorized access or suspicious input strings.
## References
- IBM DataPower XSS Bulletin: hxxps[://]www[.]ibm[.]com/support/pages/security-bulletin-ibm-datapower-gateway-affected-cross-site-scripting-cve-2026-14990
- IBM DataPower Multiple CVEs: hxxps[://]www[.]ibm[.]com/support/pages/node/7289775
- Langflow OSS Bulletin: hxxps[://]www[.]ibm[.]com/support/pages/node/7290694
- IBM Product Security Incident Response: hxxps[://]www[.]ibm[.]com/support/pages/bulletin/