CVE-2026-7876: Authentication bypass vulnerability found in Aspera High-Speed Transfer Server for Cloud Pak for Integration
IBM Aspera High-Speed Transfer Server and IBM Aspera High-Speed Transfer Endpoint are affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.
Other sources
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.
— MITRE
Affected Software
Remediation
Information
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7876?
The severity of CVE-2026-7876 is critical with a CVSS score of 9.1.
How do I fix CVE-2026-7876?
To fix CVE-2026-7876, upgrade to IBM Aspera High-Speed Transfer Server for Cloud Pak for Integration version 1.5.20 or later.
What systems are affected by CVE-2026-7876?
CVE-2026-7876 affects IBM Aspera High-Speed Transfer Server and IBM Aspera High-Speed Transfer Endpoint.
What type of vulnerability is CVE-2026-7876?
CVE-2026-7876 is an authentication bypass vulnerability.
What risk does CVE-2026-7876 pose to users?
CVE-2026-7876 allows unauthorized access to files in the server's local storage, posing significant data confidentiality and integrity risks.