CVE-2026-14996
IBM · Aspera Faspex 5
IBM Aspera Faspex 5 contains an insufficient session expiration vulnerability that could allow an unauthenticated attacker to hijack active user sessions.
Executive summary
IBM Aspera Faspex 5 is vulnerable to session hijacking due to insufficient session expiration, posing a high risk of unauthorized access.
Vulnerability
The application fails to properly expire user sessions under certain conditions, which corresponds to CWE-613. This flaw allows an unauthenticated attacker to potentially access active sessions without proper authorization.
Business impact
With a CVSS score of 8.2, this vulnerability represents a significant risk to data confidentiality. Unauthorized access to active sessions could allow an attacker to exfiltrate sensitive files or perform administrative actions within the Aspera Faspex environment.
Remediation
Immediate Action: Upgrade IBM Aspera Faspex to version 5.0.16 or later as specified in the vendor advisory.
Proactive Monitoring: Monitor user session logs for unusual login times, multiple concurrent sessions from different IP addresses for the same user, or suspicious file transfer activity.
Compensating Controls: Implement strict network access controls to limit access to the Faspex interface to trusted IP ranges only.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Organizations utilizing IBM Aspera Faspex must perform the update to version 5.0.16 immediately to ensure session integrity. Regular patching of this platform is essential to prevent unauthorized access to high-value data transfers.