CVE-2026-14959: OS Command Injection in IBM Aspera Faspex
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
Other sources
IBM Aspera Faspex 5 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Aspera Faspex 5to a version that resolves this vulnerability.Fixed in 5.0.16Patch OS Command Injection in IBM Aspera Faspex
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14959?
CVE-2026-14959 has a critical severity rating of 9.1.
How do I fix CVE-2026-14959?
To fix CVE-2026-14959, upgrade IBM Aspera Faspex to the latest patched version provided by IBM.
Who is affected by CVE-2026-14959?
CVE-2026-14959 affects all versions of IBM Aspera Faspex from 5.0.0 to 5.0.15.4.
What type of vulnerability is CVE-2026-14959?
CVE-2026-14959 is an OS command injection vulnerability that allows attackers to execute arbitrary code.
What can an attacker achieve with CVE-2026-14959?
An authenticated attacker can exploit CVE-2026-14959 to execute arbitrary commands on the server.