CVE-2026-9035: Multiple vulnerabilities in Aspera applications.
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to.
Other sources
IBM Aspera High-Speed Transfer Server and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Aspera High-Speed Transfer Serverto a version that resolves this vulnerability.Fixed in 4.4.7 Fix Pack 2Patch Fix Pack 2 - Upgrade
Upgrade
IBM Aspera High-Speed Transfer Endpointto a version that resolves this vulnerability.Fixed in 4.4.7 Fix Pack 2Patch Fix Pack 2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9035?
The severity of CVE-2026-9035 is rated medium with a score of 6.5.
What type of vulnerability is described in CVE-2026-9035?
CVE-2026-9035 describes a path traversal vulnerability in Aspera applications.
How do I fix CVE-2026-9035?
To fix CVE-2026-9035, upgrade to IBM Aspera High-Speed Transfer Server and Endpoint version 4.4.7 Fix Pack 2.
What components of Aspera applications are affected by CVE-2026-9035?
CVE-2026-9035 affects the asperahttpd component of IBM Aspera High-Speed Transfer Endpoint and Server.
Can an authenticated user exploit CVE-2026-9035?
Yes, an authenticated user may exploit CVE-2026-9035 to potentially read arbitrary files.