Shell Command Injection in IBM Aspera Faspex 5 Product
CVE-2026-14959

9.1CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 July 2026

What is CVE-2026-14959?

IBM Aspera Faspex versions 5.0.0 through 5.0.15.4 are susceptible to a shell command injection vulnerability that could allow an authenticated remote attacker to execute arbitrary code through crafted input. This can significantly compromise the integrity of the application and expose sensitive data if exploited. Users are advised to patch their systems promptly to mitigate security risks.

Affected Version(s)

Aspera Faspex 5 5.0.0 <= 5.0.15.4

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.