CVE-2026-75777 PUBLISHED

Multiple vulnerabilities in IBM Aspera Enterprise Webapps

Assigner: ibm
Reserved: 18.08.2026 Published: 10.09.2026 Updated: 10.09.2026

IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor IBM
Product Aspera Enterprise WebApps
Versions
  • affected from 1.0.0 to 1.0.5 (incl.)

Solutions

IBM strongly recommends addressing the vulnerabilities now by upgrading to IBM Aspera Enterprise WebApps 1.0.6 available from the link below

ProductFixing VRMPlatformLink to FixIBM Aspera Enterprise WebApps1.0.6

Linux Link https://www.ibm.com/support/fixcentral/swg/selectFixes

References

Problem Types

  • CWE-269 Improper Privilege Management CWE