CVE-2026-75878: IBM Sterling File Gateway is Vulnerable to Authentication Bypass
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.0.6_2Patch IT49865 - Upgrade
Upgrade
IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.1.2_1Patch IT49865 - Upgrade
Upgrade
IBM Sterling File Gatewayto a version that resolves this vulnerability.Fixed in 6.2.2.1_1Patch IT49865 - Compensating control
For IBM Sterling File Gateway 6.2.0.6_2, contact IBM support (per vulnerability remediation guidance).
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable over the network and requires no prior privileges or user interaction. Exploitation involves an unvalidated SSO header and can result in a fully authenticated session.