Junglewise Threat Intelligence

CVE-2026-14973: IBM Aspera Desktop App path traversal in download destination

CVE-2026-14973 · Severity: critical · CVSS 9.3 · Published 2026-07-28

Executive brief

IBM Aspera Desktop App, a high-speed file transfer tool, contains a vulnerability that allows files to be written to unauthorized locations on a user's computer. An attacker could exploit this to place malicious files outside of the intended download folder, potentially leading to system compromise or data loss. This issue affects users who interact with a malicious download source or link.

Technical details

A path traversal vulnerability (CWE-22) exists in the IBM Aspera Desktop App versions 1.0.5 through 1.0.19. The application fails to properly sanitize file paths during download operations, allowing a remote attacker to write files to arbitrary locations on the local filesystem outside of the designated download directory. Exploitation requires minimal user interaction, such as a user initiating a download from a malicious source. This can result in high confidentiality and integrity impacts, as an attacker could overwrite sensitive system files or plant executable malware. The issue is resolved in version 1.1.0.

Affected products

  • IBM Aspera Desktop App 1.0.5 - 1.0.19

Timeline

  • 2026-07-23: advisory: Initial IBM publication
  • 2026-07-28: disclosed: NVD publication
  • 2026-07-23: patched: Version 1.1.0 released

References

Related threats