CVE-2026-9035

MEDIUM

IBM Aspera High-Speed Transfer Endpoint - Multiple Vulnerabilities in Aspera applications.

Title source: rule
STIX 2.1

Description

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7273615

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 22.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (6)
IBM/Aspera High-Speed Transfer Endpoint 3.7.4 - 4.4.7 Fix Pack 1
IBM/Aspera High-Speed Transfer Server 3.7.4 - 4.4.7 Fix Pack 1
ibm/aspera_high-speed_transfer_endpoint 4.4.7 (2 CPE variants)
ibm/aspera_high-speed_transfer_endpoint 3.7.4 - 4.4.6
ibm/aspera_high-speed_transfer_server 4.4.7 (2 CPE variants)
ibm/aspera_high-speed_transfer_server 3.7.4 - 4.4.6
Published May 27, 2026
Tracked Since May 27, 2026