PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9035 IBM CVE debrief

IBM Aspera High-Speed Transfer Endpoint and Server versions 3.7.4 through 4.4.7 Fix Pack 1 contain an arbitrary file read vulnerability in the asperahttpd component. An authenticated attacker can exploit path traversal weaknesses (CWE-22) to access files outside intended directories on the server's local storage. The vulnerability requires network access and valid credentials, with no user interaction needed. IBM has released security updates addressing this issue.

Vendor
IBM
Product
Aspera High-Speed Transfer Endpoint
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-27
Original CVE updated
2026-05-27
Advisory published
2026-05-27
Advisory updated
2026-05-27

Who should care

Organizations running IBM Aspera High-Speed Transfer Endpoint or Server versions 3.7.4 through 4.4.7 Fix Pack 1, particularly those exposing asperahttpd services to untrusted networks or with multi-tenant user environments.

Technical summary

The asperahttpd component in IBM Aspera High-Speed Transfer Endpoint 3.7.4-4.4.7 FP1 and Server 3.7.4-4.4.7 FP1 is vulnerable to path traversal (CWE-22). Authenticated attackers can read arbitrary files from server local storage. CVSS 3.1: 6.5 (Medium). Network exploitable with low complexity and low privileges required.

Defensive priority

medium

Recommended defensive actions

  • Apply IBM Aspera High-Speed Transfer Endpoint or Server updates to version 4.4.7 Fix Pack 2 or later
  • Restrict network access to asperahttpd services to authorized administrative hosts
  • Review file system permissions to ensure least privilege access
  • Monitor asperahttpd access logs for anomalous file access patterns
  • Validate that web server configurations block directory traversal sequences

Evidence notes

CWE-22 (Path Traversal) identified as the root cause. CVSS 3.1 vector confirms network attack vector, low attack complexity, and low privileges required. IBM PSIRT is the authoritative source.

Official resources

IBM disclosed this vulnerability on May 27, 2026. The affected products are enterprise file transfer solutions used for high-speed data movement. The asperahttpd component, which provides HTTP-based transfer capabilities, fails to properly