CVE-2026-14958: OS command injection in IBM Aspera Faspex
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
Other sources
IBM Aspera Faspex 5 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Aspera Faspex 5to a version that resolves this vulnerability.Fixed in 5.0.16