Path Traversal Vulnerability in IBM Aspera Desktop App
CVE-2026-14973

9.3CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
28 July 2026

What is CVE-2026-14973?

A path traversal vulnerability exists in the IBM Aspera Desktop App versions 1.0.5 through 1.0.19, allowing attackers to write files to locations outside the user's designated download directory. This flaw can lead to unauthorized access to sensitive files and data exposure, posing significant risks to user privacy and security. Users are advised to update to the latest version to mitigate this vulnerability.

Affected Version(s)

Aspera Desktop App 1.0.5 <= 1.0.19

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.