← Vulnerability feed

Vulnerability record · CVE-2026-7876 · published 27 May 2026

CVE-2026-7876: Ibm aspera high-speed transfer server for cloud pak for integration improper authentication vulnerability

Ibm · Aspera High Speed Transfer Server For Cloud Pak For Integration

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.

9.1 CVSS 3.1 Critical EPSS 0.50% · top 59.5% CWE-287 · Improper authentication
9.1CVSS 3.1 base score
0.50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage that they should not have access to, when specific restriction settings are not in place.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.ibm.com/support/pages/node/7274127 PatchVendor Advisory

Track CVE-2026-7876 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-4433Ibm aspera application platform on demand improper input validation vulnerabilityCertain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attack…EPSS 5.1%7.5CVE-2020-4434Ibm aspera application platform on demand classic buffer overflow vulnerabilityCertain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an a…EPSS 2.6%7.5CVE-2020-4435Ibm aspera application platform on demand out-of-bounds write vulnerabilityCertain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with …EPSS 1.6%7.5CVE-2020-4436Ibm aspera application platform on demand classic buffer overflow vulnerabilityCertain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge o…EPSS 3.1%7.5CVE-2020-4432Ibm aspera application platform on demand command injection vulnerabilityCertain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge…EPSS 3.4%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed

Source: NIST National Vulnerability Database (record CVE-2026-7876), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.