CVE-2026-7876
critical · 9.1IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.
9.1
CVSS
0.3%
EPSS (exploit prob.)
24th
EPSS percentile
2026-05-27
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | aspera_high-speed_transfer_server_for_cloud_pak_for_integration | >= 1.5.1, < 1.5.20 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-7876