CVE-2026-14959: OS Command Injection in IBM Aspera Faspex
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
Other sources
IBM Aspera Faspex 5 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Aspera Faspex 5to a version that resolves this vulnerability.Fixed in 5.0.16Patch OS Command Injection in IBM Aspera Faspex