CVE 6.5 MEDIUM

Multiple vulnerabilities in Aspera applications._CVE-2026-9035

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to.

Basic Information

ID CVE-2026-9035
Source ibm
Published May 27, 2026 at 13:21

Affected Product

Vendor IBM
Product Aspera High-Speed Transfer Endpoint
Version 3.7.4
Affected Versions IBM Aspera High-Speed Transfer Endpoint 3.7.4
IBM Aspera High-Speed Transfer Server 3.7.4

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.