Junglewise Threat Intelligence

CVE-2026-7253: IBM Watson Speech Services Cartridge SSRF in Sterling File Gateway

CVE-2026-7253 · Severity: medium · CVSS 5.3 · Published 2026-06-22

Vendors: IBM.

Executive brief

IBM Watson Speech Services Cartridge, which provides AI-driven speech-to-text and text-to-speech capabilities, is affected by a security flaw in its Sterling File Gateway component. An authenticated user could exploit this to send unauthorized requests from the server to internal or external systems. This could allow an attacker to map out internal network structures or gain access to sensitive information not intended for public exposure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Sterling File Gateway component of IBM Watson Speech Services Cartridge versions 4.0.0 through 5.3.1. The flaw (CWE-918) allows an authenticated attacker with low privileges to submit crafted requests that the server then executes. Due to high attack complexity, the exploit requires specific environmental conditions to succeed. If successful, an attacker can use the server as a proxy to probe internal network services or facilitate further attacks. The vulnerability has been addressed in version 5.4 and version 5.3.1 Patch 7.

Affected products

  • IBM Watson Speech Services Cartridge 4.0.0 - 5.3.1

Timeline

  • 2026-06-18: disclosed: Initial publication by IBM
  • 2026-06-18: patched: Fixes released in version 5.4 and 5.3.1 Patch 7
  • 2026-06-22: advisory: NVD publication date

References