top of page
perceptive_background_267k.jpg

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

Published:

28 July 2026 at 00:00:00

Alert date:

29 July 2026 at 00:02:06

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

CVE-2026-14958 affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4. The vulnerability allows a remote authenticated attacker to execute arbitrary code on the affected system. The root cause is unquoted shell interpolation within the application. Successful exploitation requires the attacker to be authenticated. IBM has published a support advisory with remediation guidance. The issue is rated high severity given the potential for arbitrary code execution. Organizations using affected versions should apply the recommended patches or mitigations promptly.

Technical details

Mitigation steps:

Affected products:

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page