PatchSiren cyber security CVE debrief
CVE-2026-9035 IBM CVE debrief
IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 contain an arbitrary file read vulnerability in the asperahttpd component. An authenticated attacker can exploit path traversal weaknesses (CWE-22) to access files outside intended directories on the server's local storage. The vulnerability requires network access and valid credentials, with no user interaction needed. IBM has released security updates addressing this issue.
- Vendor
- IBM
- Product
- Aspera High-Speed Transfer Endpoint
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-06-05
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-06-05
Who should care
Organizations running IBM Aspera High-Speed Transfer Endpoint or Server versions 3.7.4 through 4.4.7 Fix Pack 1, particularly those exposing asperahttpd services to untrusted networks or with multi-tenant user environments.
Technical summary
The asperahttpd component in IBM Aspera High-Speed Transfer Endpoint 3.7.4-4.4.7 FP1 and Server 3.7.4-4.4.7 FP1 is vulnerable to path traversal (CWE-22). Authenticated attackers can read arbitrary files from server local storage. CVSS 3.1: 6.5 (Medium). Network exploitable with low complexity and low privileges required.
Defensive priority
medium
Recommended defensive actions
- Apply IBM Aspera High-Speed Transfer Endpoint or Server updates to version 4.4.7 Fix Pack 2 or later
- Restrict network access to asperahttpd services to authorized administrative hosts
- Review file system permissions to ensure least privilege access
- Monitor asperahttpd access logs for anomalous file access patterns
- Validate that web server configurations block directory traversal sequences
Evidence notes
CWE-22 (Path Traversal) identified as the root cause. CVSS 3.1 vector confirms network attack vector, low attack complexity, and low privileges required. IBM PSIRT is the authoritative source.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9035 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9035
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9035 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9035
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7273615
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.