Junglewise Threat Intelligence

CVE-2026-14996: IBM Aspera Faspex insufficient session expiration

CVE-2026-14996 · Severity: high · CVSS 8.2 · Published 2026-07-28

Technologies: IBM Aspera Faspex. Vendors: IBM.

Executive brief

IBM Aspera Faspex 5, a high-speed file transfer and collaboration platform, contains a session management vulnerability. This flaw could allow an unauthorized user to maintain access to the system longer than intended or potentially hijack active sessions. An exploit could lead to unauthorized access to sensitive files and data managed by the platform.

Technical details

IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 are vulnerable to insufficient session expiration (CWE-613). The flaw resides in the session management component, where sessions may not be properly invalidated or expired. A remote, unauthenticated attacker can exploit this to gain unauthorized access to sensitive information or perform unauthorized actions by leveraging active or improperly terminated sessions. The vulnerability is addressed in IBM Aspera Faspex version 5.0.16.

Affected products

  • IBM Aspera Faspex 5 5.0.0 through 5.0.15.4

Timeline

  • 2026-07-28: advisory: IBM published the security bulletin and NVD record.
  • 2026-07-28: patched: Vulnerability addressed in version 5.0.16.

References

Related threats