CVE-2026-75777

8.8

IBM · Aspera Enterprise WebApps

IBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5 contain a vulnerability that allows local attackers to escape container protections via unrestricted system calls.

Executive summary

A high-severity container escape vulnerability in IBM Aspera Enterprise WebApps could allow a local attacker to gain elevated control over the host system.

Vulnerability

The application is susceptible to improper privilege management (CWE-269) because it permits unrestricted system calls within its containerized environment. This flaw requires the attacker to have local access to the system to execute the necessary calls for container breakout.

Business impact

A successful exploit allows an attacker to bypass container isolation, potentially leading to full compromise of the underlying host operating system. Given the CVSS score of 8.8, this vulnerability poses a significant risk to data confidentiality, system integrity, and availability, as unauthorized access to the host environment can be leveraged for lateral movement or persistence across the corporate infrastructure.

Remediation

Immediate Action: Upgrade to IBM Aspera Enterprise WebApps version 1.0.6 immediately, as specified in the official IBM security advisory.

Proactive Monitoring: Review system logs for unusual system call patterns or unauthorized attempts to access host-level resources from the application container.

Compensating Controls: Implement strict kernel-level security policies such as AppArmor or SELinux profiles to restrict the system calls available to the container process.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a critical security gap that undermines the core isolation benefits of containerization. Administrators must prioritize the deployment of version 1.0.6 across all affected environments to mitigate the risk of host-level privilege escalation. Failure to patch these instances could provide an entry point for attackers to gain persistent, elevated access to the underlying server infrastructure.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources