Junglewise Threat Intelligence

CVE-2026-9035: IBM Aspera High-Speed Transfer path traversal in asperahttpd

CVE-2026-9035 · Severity: medium · CVSS 6.5 · Published 2026-05-27

Technologies: IBM Aspera High-Speed Transfer Server, IBM Aspera High-Speed Transfer Endpoint. Vendors: IBM.

Executive brief

IBM Aspera High-Speed Transfer Server and Endpoint, which are used for rapid large-scale data transfers, contain a vulnerability that could allow an authorized user to read sensitive files they are not permitted to see. By exploiting this flaw, a user with basic login credentials could access internal system files or other users' data stored on the server. This could lead to the exposure of confidential business information or system configuration details.

Technical details

A path traversal vulnerability (CWE-22) exists in the asperahttpd component of IBM Aspera High-Speed Transfer Server and Endpoint. The flaw allows an authenticated attacker with network access to bypass directory restrictions by submitting specially crafted requests. Successful exploitation enables the attacker to read arbitrary files from the server's local storage that should be inaccessible to their user level. The vulnerability is addressed in version 4.4.7 Fix Pack 2.

Affected products

  • IBM Aspera High-Speed Transfer Endpoint 3.7.4 - 4.4.7 Fix Pack 1
  • IBM Aspera High-Speed Transfer Server 3.7.4 - 4.4.7 Fix Pack 1

Timeline

  • 2026-05-21: advisory: Initial publication by IBM
  • 2026-05-22: other: Updated product versions in documentation
  • 2026-05-27: disclosed: NVD publication date

References

Related threats