IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7274127 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place. |
29 May 2026, 21:25
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:ibm:aspera_high-speed_transfer_server_for_cloud_pak_for_integration:*:*:*:*:*:*:*:* | |
| First Time |
Ibm aspera High-speed Transfer Server For Cloud Pak For Integration
Ibm |
|
| References | () https://www.ibm.com/support/pages/node/7274127 - Patch, Vendor Advisory |
28 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
27 May 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 14:17
Updated : 2026-06-17 11:03
NVD link : CVE-2026-7876
Mitre link : CVE-2026-7876
CVE.ORG link : CVE-2026-7876
JSON object : View
Products Affected
ibm
- aspera_high-speed_transfer_server_for_cloud_pak_for_integration
CWE
