Description
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
Published: 2026-07-28
Score: 9.1 Critical
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 contain a command injection flaw that allows a remote authenticated attacker to execute arbitrary shell commands. The weakness arises from improper validation of input that is passed directly to the operating system shell, making the application vulnerable to CWE‑78. Successful exploitation would grant the attacker full control over the underlying host, compromising confidentiality, integrity, and availability of the server and any data it services.

Affected Systems

Systems running IBM Aspera Faspex version 5.0.0 up to and including 5.0.15.4 on Linux are impacted. The issue does not affect other vendors or product lines according to the CNA data. Administrators should review their deployments for these specific versions.

Risk and Exploitability

The CVSS severity score is 9.1, indicating a critical vulnerability. The EPSS score of 1% suggests a low but realistic probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a remote authenticated session, implying that an attacker must first gain valid credentials to the Faspex service. Once authenticated, the attacker can inject malicious commands that the application will execute with the privileges of the Faspex process.

Generated by OpenCVE AI on August 3, 2026 at 14:18 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading: ProductVersionPlatformLink to FixIBM Aspera Faspex5.0.16Linux Link https://www.ibm.com/support/fixcentral/swg/downloadFixes


OpenCVE Recommended Actions

  • Apply the IBM‑provided patch by upgrading to at least version 5.0.16 for Linux.
  • Restrict access to the Faspex service by applying network segmentation and limiting authentication to authorized personnel.
  • Configure the application to run with the minimal required privileges and disable unnecessary features that may expose command execution.

Generated by OpenCVE AI on August 3, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
Title OS Command Injection in IBM Aspera Faspex
First Time appeared Ibm
Ibm aspera Faspex 5
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:aspera_faspex_5:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:aspera_faspex_5:5.0.15.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm aspera Faspex 5
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Aspera Faspex Aspera Faspex 5
Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T03:55:27.073Z

Reserved: 2026-07-07T14:21:25.182Z

Link: CVE-2026-14959

cve-icon Vulnrichment

Updated: 2026-07-29T13:38:14.707Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T21:17:26.443

Modified: 2026-08-05T15:58:31.347

Link: CVE-2026-14959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:30:18Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')