
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-14958 is an OS command injection vulnerability in IBM Aspera Faspex 5 that allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation. It affects IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 (running on Linux). The vulnerability was disclosed on July 28, 2026, with IBM's advisory published the same day. CVSS v3.1 scores differ by source: NVD rates it 7.2 (High) while IBM (CNA) rates it 9.1 (Critical) (IBM Advisory, GitHub Advisory).
The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), specifically arising from unquoted shell interpolation within the application. When user-controlled input is incorporated into shell commands without proper quoting or sanitization, an attacker can inject additional shell metacharacters or commands that alter the intended command execution. Exploitation requires network access and high-privilege (authenticated) credentials, but no user interaction is needed. No public proof-of-concept code has been identified at this time (IBM Advisory, GitHub Advisory).
Successful exploitation grants the attacker arbitrary code execution on the underlying Linux host running IBM Aspera Faspex 5, with potential for full confidentiality, integrity, and availability compromise. An attacker could exfiltrate sensitive file transfer data, modify or destroy files managed by the Faspex platform, or disrupt service availability. IBM's CNA scoring (Scope: Changed) suggests the impact may extend beyond the vulnerable component itself, potentially enabling lateral movement within the hosting environment (IBM Advisory, GitHub Advisory).
No public exploit code or in-the-wild exploitation has been reported as of the time of disclosure. CISA's SSVC assessment classifies exploitation as "none" and the attack as non-automatable, indicating no known active exploitation (IBM Advisory). The EPSS score is approximately 0.52% (41st percentile), reflecting a low-to-moderate near-term exploitation probability. Exploitation requires high privileges (authenticated attacker), which limits the attack surface compared to unauthenticated vulnerabilities (GitHub Advisory).
;, $(...), `) into the vulnerable parameter to append or substitute arbitrary OS commands.;, $(), backticks) in request parameters; authentication events from unusual source IPs using high-privilege accounts./bin/bash, curl, wget, nc, python) on the Linux host./tmp; presence of web shells, reverse shell scripts, or unauthorized cron jobs created by the Faspex service account.IBM has released a patch in version 5.0.16, which addresses this vulnerability; organizations should upgrade IBM Aspera Faspex 5 to version 5.0.16 or later as the primary remediation (IBM Advisory). As interim mitigations, restrict access to the Faspex web interface to trusted IP ranges and enforce the principle of least privilege for administrative accounts to reduce the attack surface. Monitor IBM's support portal for additional guidance or supplementary patches (IBM Support).
IBM published a security bulletin addressing multiple vulnerabilities in IBM Aspera Faspex, including CVE-2026-14958, on July 20, 2026 (IBM Advisory). Security news outlet SecurityOnline.info covered the IBM Aspera Faspex vulnerabilities shortly after disclosure. No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."