Junglewise Threat Intelligence

CVE-2026-14958: IBM Aspera Faspex OS command injection via shell interpolation

CVE-2026-14958 · Severity: critical · CVSS 9.1 · Published 2026-07-28

Technologies: IBM Aspera Faspex. Vendors: IBM.

Executive brief

IBM Aspera Faspex 5, a high-speed file transfer solution, is vulnerable to a security flaw that could allow an authorized user to take control of the server. By exploiting a weakness in how the system processes commands, an attacker with high-level permissions can execute unauthorized code. This could lead to a complete compromise of the system, including the theft of sensitive data or disruption of file transfer operations.

Technical details

IBM Aspera Faspex 5 (versions 5.0.0 through 5.0.15.4) is vulnerable to OS command injection (CWE-78) resulting from unquoted shell interpolation. A remote authenticated attacker with high privileges (PR:H) can exploit this vulnerability to execute arbitrary commands on the underlying operating system. The vulnerability is characterized by a scope change (S:C), indicating that an exploit can impact components beyond the Faspex application itself. IBM has addressed this issue in version 5.0.16.

Affected products

  • IBM Aspera Faspex 5 5.0.0 through 5.0.15.4

Timeline

  • 2026-07-28: advisory: IBM published the security bulletin and NVD record.
  • 2026-07-28: patched: Vulnerability addressed in version 5.0.16.

References

Related threats