Description
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
Published: 2026-07-28
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw in IBM Aspera Faspex 5 allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. The vulnerability is rooted in improper handling of shell arguments, which can lead to the execution of unintended system commands. This capability enables a threat actor to compromise confidentiality, integrity, or availability of the affected host if the injection succeeds.

Affected Systems

IBM Aspera Faspex 5, versions 5.0.0 through 5.0.15.4 on Linux platforms, is vulnerable to this flaw. The affected releases are listed in the CPE entries for 5.0.0 and 5.0.15.4, and the issue applies to the Linux deployment of the product.

Risk and Exploitability

The CVSS score of 9.1 places the vulnerability in the high‑impact category, while the EPSS score of less than 1% indicates a low probability of exploitation at present time. The flaw requires an attacker to possess authenticated access to the application’s interface; under those conditions, the unauthenticated portion of the command injection is mitigated. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants urgent remediation regardless of the low EPSS figure.

Generated by OpenCVE AI on August 4, 2026 at 12:48 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading: ProductVersionPlatformLink to FixIBM Aspera Faspex5.0.16Linux Link https://www.ibm.com/support/fixcentral/swg/downloadFixes


OpenCVE Recommended Actions

  • Upgrade IBM Aspera Faspex to version 5.0.16 or later on Linux environments. This is the official fix issued by IBM.
  • Restrict external access to the Faspex application by using firewall rules or by placing the service behind a VPN or reverse proxy until a patch is applied.
  • If upgrading cannot be performed immediately, audit any custom scripts or modules for proper quoting of shell arguments, and apply input validation or escaping to eliminate unquoted interpolation.

Generated by OpenCVE AI on August 4, 2026 at 12:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
Title OS command injection in IBM Aspera Faspex
First Time appeared Ibm
Ibm aspera Faspex 5
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:aspera_faspex_5:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex_5:5.0.15.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Faspex 5
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Aspera Faspex Aspera Faspex 5
Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T03:55:26.302Z

Reserved: 2026-07-07T14:06:56.053Z

Link: CVE-2026-14958

cve-icon Vulnrichment

Updated: 2026-07-29T13:57:53.765Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T21:17:26.317

Modified: 2026-08-05T15:59:43.167

Link: CVE-2026-14958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:00:11Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')