


Perceptive Security
SOC/SIEM Consultancy

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
Published:
27 July 2026 at 22:00:00
Alert date:
28 July 2026 at 22:02:06
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
CVE-2026-14958 affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4. The vulnerability allows a remote authenticated attacker to execute arbitrary code on the affected system. The root cause is unquoted shell interpolation within the application. Successful exploitation requires the attacker to be authenticated. IBM has published a support advisory with remediation guidance. The issue is rated high severity given the potential for arbitrary code execution. Organizations using affected versions should apply the recommended patches or mitigations promptly.
Technical details
Mitigation steps:
Affected products:
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
