PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9035 IBM CVE debrief

IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 contain an arbitrary file read vulnerability in the asperahttpd component. An authenticated attacker can exploit path traversal weaknesses (CWE-22) to access files outside intended directories on the server's local storage. The vulnerability requires network access and valid credentials, with no user interaction needed. IBM has released security updates addressing this issue.

Vendor
IBM
Product
Aspera High-Speed Transfer Endpoint
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-06-05
Advisory published
2026-05-27
Advisory updated
2026-06-05

Who should care

Organizations running IBM Aspera High-Speed Transfer Endpoint or Server versions 3.7.4 through 4.4.7 Fix Pack 1, particularly those exposing asperahttpd services to untrusted networks or with multi-tenant user environments.

Technical summary

The asperahttpd component in IBM Aspera High-Speed Transfer Endpoint 3.7.4-4.4.7 FP1 and Server 3.7.4-4.4.7 FP1 is vulnerable to path traversal (CWE-22). Authenticated attackers can read arbitrary files from server local storage. CVSS 3.1: 6.5 (Medium). Network exploitable with low complexity and low privileges required.

Defensive priority

medium

Recommended defensive actions

  • Apply IBM Aspera High-Speed Transfer Endpoint or Server updates to version 4.4.7 Fix Pack 2 or later
  • Restrict network access to asperahttpd services to authorized administrative hosts
  • Review file system permissions to ensure least privilege access
  • Monitor asperahttpd access logs for anomalous file access patterns
  • Validate that web server configurations block directory traversal sequences

Evidence notes

CWE-22 (Path Traversal) identified as the root cause. CVSS 3.1 vector confirms network attack vector, low attack complexity, and low privileges required. IBM PSIRT is the authoritative source.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9035 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9035

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9035 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9035

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.