CVE-2026-14958
IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 contain a flaw that lets a logged‑in attacker run arbitrary commands on the server. The issue is caused by unquoted shell interpolation, which can be exploited to execute code. It is rated critical with a CVSS score of 9.1.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
IBM Aspera Faspex 5, versions 5.0.0 to 5.0.15.4, used by organizations that rely on Aspera's high‑speed file transfer service.
Real-world impact
An attacker who can authenticate to the system could run any commands, potentially taking full control of the server, stealing data, or disrupting services.
Why this severity
The CVSS score of 9.1 reflects that the flaw is exploitable over the network, requires only low effort, and gives an attacker high privileges to compromise confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources