CVE-2026-75878 PUBLISHED

IBM Sterling File Gateway is Vulnerable to Authentication Bypass

Assigner: ibm
Reserved: 18.08.2026 Published: 18.09.2026 Updated: 18.09.2026

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Score: 9.1

Product Status

Vendor IBM
Product Sterling File Gateway
Versions
  • affected from 6.2.0.0 to 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 (incl.)

Solutions

IBM strongly recommends addressing the vulnerability now.

Product

VersionAPARRemediation & FixIBM Sterling File Gateway6.2.0.0 - 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1IT49865Apply 6.2.0.6_2, 6.2.1.2_1 or 6.2.2.1_1

The IIM versions 6.2.1.2_1 and 6.2.2.1_1 are available on  Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes . 

The container versions of 6.2.1.2_1 and 6.2.2.1_1 are available in IBM Entitled Registry

  • cp.icr.io/cp/ibm-sfg for IBM Sterling File Gateway

For 6.2.0.6_2, contact the support

References

Problem Types

  • CWE-287 Improper Authentication CWE