Arbitrary Code Execution Vulnerability in IBM Aspera Desktop App
CVE-2026-11980

7.3HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 July 2026

What is CVE-2026-11980?

The IBM Aspera Desktop App versions 1.0.5 through 1.0.19 is susceptible to a critical vulnerability that allows arbitrary code execution. This issue arises from the application's ability to load DLL files during startup, which can be exploited by attackers to run malicious code. It is essential for users of these affected versions to apply recommended patches and updates to mitigate potential security risks.

Affected Version(s)

Aspera Desktop App 1.0.5 <= 1.0.19

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.