IBM has disclosed a critical (CVSS 9.1) shell command injection flaw in Aspera Faspex 5 that, according to the vendor's advisory, could allow a remote authenticated attacker to execute arbitrary code on the underlying host. The record has not yet completed independent analysis, so the impact description rests on IBM's own characterization.
What Is It
CVE-2026-14959 is described as an OS command injection vulnerability (CWE-78) in IBM Aspera Faspex 5, the managed file transfer web application. Per IBM's PSIRT, versions 5.0.0 through 5.0.15.4 "could allow a remote authenticated attacker to execute arbitrary code due to shell command injection."
The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, base score 9.1, rated CRITICAL. Attack is over the network with low complexity and no user interaction, but requires high privileges. The score is driven up by a changed scope (S:C), meaning successful exploitation is assessed to impact components beyond the vulnerable application itself, with high confidentiality, integrity, and availability impact. These metrics are vendor-supplied and have not been independently reassessed.
Why It Matters
If the flaw behaves as described, command injection in a file transfer platform means an attacker who reaches the injection point would be executing shell commands in the context of the service, and the changed-scope rating indicates that impact is expected to extend past the app boundary. Aspera Faspex typically sits at network edges handling large-volume data movement, so the data exposed to a code-execution flaw here is exactly the data organizations chose to move through a dedicated transfer product.
The PR:H requirement is the one meaningful brake: exploitation is stated to need high-privilege access. That reduces the pool of attackers who could trigger it, but does not help against credential compromise or a malicious insider.
No CISA KEV entry was supplied for this CVE. There is no confirmation of active exploitation in the provided source material, and no KEV-mandated remediation deadline.
What's Vulnerable
- Vendor: IBM
- Product: Aspera Faspex 5
- Affected versions: 5.0.0 through 5.0.15.4 (inclusive, semver range)
No other IBM products are listed as affected in the supplied record.
Patch Status
IBM published a security bulletin at support node 7280530. The NVD record was published 2026-07-28 with a status of "Received," meaning it has not yet completed NVD analysis and the details above may change. No fixed version number is specified in the supplied data; consult the IBM bulletin directly for the remediation build and upgrade path.
Sources
- NVD, CVE-2026-14959: https://nvd.nist.gov/vuln/detail/CVE-2026-14959
- IBM Security Bulletin ([email protected]): https://www.ibm.com/support/pages/node/7280530