CVE-2026-14973: Path Traversal in IBM Desktop App
Published Jul 23, 2026
·Updated
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
Affected Software
6 affected components
IBM Aspera Desktop App>=1.0.5<=1.0.19
IBM Aspera Desktop App<=1.0.5 - 1.0.19
All of the following
IBM Aspera>=1.0.5<=1.0.19
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Aspera Desktop Appto a version that resolves this vulnerability.Fixed in 1.1.0
Event History
Jul 23, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Jul 28, 2026
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-14973?
CVE-2026-14973 has a critical severity rating of 9.3.
2
How do I fix CVE-2026-14973?
To fix CVE-2026-14973, ensure you update IBM Aspera Desktop App to version 1.0.20 or later.
3
What type of vulnerability is CVE-2026-14973?
CVE-2026-14973 is a path traversal vulnerability.
4
What versions of IBM Aspera Desktop App are affected by CVE-2026-14973?
IBM Aspera Desktop App versions 1.0.5 through 1.0.19 are affected by CVE-2026-14973.
5
What could an attacker do by exploiting CVE-2026-14973?
An attacker could exploit CVE-2026-14973 to write files outside of the user's selected download destination.