External risk intelligence

IBM DataPower Gateway Cross-Site Scripting Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-14990

IBM DataPower Gateway is an internet-facing appliance typically deployed as an API gateway, reverse proxy, or integration edge service. The vulnerability exists within the Web UI, which is a management interface that, while often protected, is designed for administrative access in network-connected environments, making the product's role inherently internet-adjacent or public-facing by design.

Cross-site Scripting

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

IBM DataPower Gateway's web interface has a vulnerability that could allow an attacker to inject malicious code, potentially exposing sensitive information within a user's session. The main concern is confirming if this specific technology is in use and if it is exposed.

  • Unauthenticated users can run malicious code.
  • It affects web interfaces of IBM DataPower Gateway.
  • Confirm relevance and exposure of this technology.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could embed malicious JavaScript within the DataPower Gateway's Web UI. This could modify the interface's behavior, potentially exposing user credentials during a legitimate session.

  • No authentication required.
  • Inject JavaScript into Web UI.
  • Credentials disclosure risk.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated user could inject malicious JavaScript into the Web UI, potentially altering its functionality. This could lead to the disclosure of credentials within a legitimate user's session when supported by the advisory.

  • Web UI and user sessions at risk.
  • Malicious JavaScript injection via Web UI.
  • Potential credential disclosure within sessions.

Operational Fix

Recommended remediation, mitigation, and detection steps

IBM DataPower Gateway owners and platform teams should lead the response to this critical cross-site scripting vulnerability. The initial focus should be on identifying all deployed instances, assessing their exposure and business criticality, and confirming the responsible owner for remediation planning. This proactive approach ensures swift and targeted action, minimizing potential impact and credential disclosure risks.

  • Identify affected DataPower instances.
  • Verify external reachability and business impact.
  • Plan remediation with platform owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is IBM DataPower Gateway?

It is an enterprise appliance that functions as a secure gateway for APIs, acting as a reverse proxy or integration bridge. Organizations use it to manage traffic, enforce security policies, and transform data between external clients and internal systems.

What does CVE-2026-14990 mean for system security?

This CVE represents a Cross-Site Scripting (XSS) vulnerability, categorized as CWE-79. It allows an attacker to inject unauthorized JavaScript into the management Web UI, which can then execute within a logged-in user's browser session to potentially steal credentials.

How does an attacker trigger this vulnerability?

An unauthenticated attacker can attempt to inject malicious code into specific fields or elements within the Web UI. It is important to note that this flaw specifically targets the gateway's administrative management interface; it does not necessarily affect the actual API traffic or data being proxied through the appliance.

Is my DataPower deployment at risk?

Halo Surface Signal indicates that because DataPower Gateway often acts as an edge service or internet-adjacent appliance, the Web UI may be reachable by unauthorized parties. If your management interface is accessible from the internet or insecure network segments, your risk is significantly higher.

What should I do first to address this issue?

Begin by inventorying your environment to locate all active DataPower Gateway instances and determine which versions are in use. Once identified, prioritize instances with external or broad network visibility and consult your platform documentation to prepare for official security updates.

References