CVE-2026-19290: IBM Sterling File Gateway is Vulnerable to Improper Access Control
IBM Sterling File Gateway 6.2.0.0 through 6.2.0.61, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.
Other sources
IBM Sterling File Gateway could allow a remote attacker to obtain sensitive information due to improper access control.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.0.6_2 - Upgrade
Upgrade
IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.1.2_1 - Upgrade
Upgrade
IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.2.1_1 - Compensating control
If you are running IBM Sterling File Gateway 6.2.0.6_2, contact IBM support (per remediation guidance in the provided text).
Event History
Frequently Asked Questions
Which deployments are affected?
Affected versions are IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1.
Can an attacker exploit this remotely without credentials or user interaction?
Yes. The CVSS vector indicates network attack access, low attack complexity, no privileges required, and no user interaction required.
What is the expected impact of successful exploitation?
A remote attacker could obtain sensitive information. The reported impact is high confidentiality impact, with no integrity or availability impact indicated.