Junglewise Threat Intelligence

CVE-2026-75792: IBM Sterling Secure Proxy authorization bypass in admin UI

CVE-2026-75792 · Severity: medium · CVSS 4.3 · Published 2026-09-14

Vendors: IBM.

Executive brief

IBM Sterling Secure Proxy is a security gateway that manages and monitors data transfers in enterprise environments. A client-side authorization flaw allows authenticated users to view administrative user interface components they should not have access to, potentially exposing sensitive system controls and configuration details to non-admin users.

Technical details

The vulnerability is an improper authorization flaw (CWE-285) in the client-side authorization logic of IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.1.2. It requires an authenticated attacker with network access to the application to exploit. By leveraging the client-side authorization bypass, an attacker can view administrative UI components they are not authorized to access, enabling reconnaissance of system configuration and potential escalation paths. The flaw is fixed in version 6.2.1.3.

Affected products

  • IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fix available in version 6.2.1.3

References

Related threats